CVE-2026-67172: HCL BigFix Service Management is affected by multiple security vulnerabilities.
HCL BigFix Service Management is affected by an Information Disclosure vulnerability the application returns sensitive information in error messages when invalid inputs are sent to certain API endpoints . This information could enable an attacker to facilitate further attacks.
Affected Software
Event History
Frequently Asked Questions
Who can attempt to exploit this issue?
The vulnerability is remotely reachable and requires no privileges or user interaction. Exploitation requires sending invalid input to certain API endpoints, although the high attack complexity indicates additional conditions are needed.
What information could be exposed?
Sensitive information may be returned in application error messages. The disclosed information could help an attacker facilitate further attacks, but the specific data types are not identified.
Does exploitation affect system integrity or availability?
The provided severity vector indicates low confidentiality impact and no integrity or availability impact. The reported issue is limited to information disclosure through error messages.