Vulnerabilities (CVE)

Filtered by vendor Hcltech Subscribe
Filtered by product Bigfix Service Management
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-31958 1 Hcltech 1 Bigfix Service Management 2026-04-22 N/A 3.7 LOW
HCL BigFix Service Management is susceptible to HTTP Request Smuggling.  HTTP request smuggling vulnerabilities arise when websites route HTTP requests through web servers with inconsistent HTTP parsing. HTTP Smuggling exploits inconsistencies in request parsing between front-end and back-end servers, allowing attackers to bypass security controls and perform attacks like cache poisoning or request hijacking.
CVE-2025-31981 1 Hcltech 1 Bigfix Service Management 2026-04-22 N/A 5.3 MEDIUM
HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, allowing unencrypted access.  An attacker with access to the network traffic can sniff packets from the connection and uncover the data.
CVE-2025-31977 1 Hcltech 1 Bigfix Service Management 2025-10-29 N/A 5.3 MEDIUM
HCL BigFix SM is affected by cryptographic weakness due to weak or outdated encryption algorithms.  An attacker with network access could exploit this weakness to decrypt or manipulate encrypted communications under certain conditions.
CVE-2025-31972 1 Hcltech 1 Bigfix Service Management 2025-10-29 N/A 6.5 MEDIUM
HCL BigFix SM is affected by a Sensitive Information Exposure vulnerability where internal connections do not use TLS encryption which could allow an attacker unauthorized access to sensitive data transmitted between internal components.