CVE-2026-56597: HCL BigFix Service Management is affected by multiple security vulnerabilities.
HCL BigFix Service Management is affected by a Sensitive Information Leakage vulnerability, which could allow an unauthenticated attacker to extract internal IP addresses from the application's responses, enabling them to map the underlying network topology and identify potential internal targets.
Affected Software
Event History
Frequently Asked Questions
What information could an attacker obtain?
An unauthenticated attacker could extract internal IP addresses from application responses. This may help map the underlying network topology and identify potential internal targets.
Does exploitation require authentication or user interaction?
No authentication or user interaction is required. The published vector indicates network access, but exploitation has high attack complexity.
What is the direct security impact described?
The described impact is limited to disclosure of internal IP address information. No integrity or availability impact is identified.