hcltech

5 records · 0 with a public proof-of-concept

Disclosed vulnerabilities where the NVD names hcltech as an affected vendor, highest CVSS first.

  1. HIGH 7.4CVE-2026-67105

    HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to intercept unencrypted HTTP traffic between backend services, enabling the extraction of sensitive data and poten…

    bigfix service management

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 7.2CVE-2026-56589

    HCL BigFix Service Management is affected by a Stored Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject and store malicious scripts within the application that execute when a victim views the affected page, enabling session hija…

    bigfix service management

    AI risk analysis on Exploit-DB.ai →

  3. MEDIUM 5.3CVE-2026-67106

    HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two exposed API endpoints return sensitive data. This information could enable an attacker to launch further, more serious attacks.

    bigfix service management

    AI risk analysis on Exploit-DB.ai →

  4. MEDIUM 5.3CVE-2026-67104

    HCL BigFix Service Management is affected by an Information Disclosure vulnerability, which could allow an unauthenticated attacker to analyze publicly accessible JavaScript files, enabling the discovery of hidden administrative API endpoints for further targe…

    bigfix service management

    AI risk analysis on Exploit-DB.ai →

  5. LOW 2.2CVE-2026-56599

    HCL BigFix Service Management is affected by an Insecure Cookie Attribute Configuration vulnerability, which could allow an attacker to exploit missing security attributes such as SameSite, HttpOnly, Secure, and restrictive Paths, enabling Cross-Site Request F…

    bigfix service management

    AI risk analysis on Exploit-DB.ai →