VYPR

BigFix Service Management

by HCL Software

CVEs (27)

  • CVE-2025-31958LowApr 21, 2026
    risk 0.24cvss 3.7epss 0.00

    HCL BigFix Service Management is susceptible to HTTP Request Smuggling.  HTTP request smuggling vulnerabilities arise when websites route HTTP requests through web servers with inconsistent HTTP parsing. HTTP Smuggling exploits inconsistencies in request parsing between…

  • CVE-2025-31959LowMay 6, 2026
    risk 0.23cvss 3.5epss 0.00

    HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. This could lead to confidentiality and privacy risks if sensitive location information is unintentionally shared. .

  • CVE-2026-21806LowSep 18, 2026
    risk 0.20cvss 3.1epss 0.00

    HCL BigFix Service Management is affected by an Administrative Session Concurrency vulnerability. The application allows multiple simultaneous authenticated sessions for the same administrative account, which could enable an unauthorized attacker to predict or hijack valid…

  • CVE-2026-56597LowSep 18, 2026
    risk 0.20cvss 3.1epss 0.00

    HCL BigFix Service Management is affected by a Sensitive Information Leakage vulnerability, which could allow an unauthenticated attacker to extract internal IP addresses from the application's responses, enabling them to map the underlying network topology and identify…

  • CVE-2026-56595LowSep 18, 2026
    risk 0.20cvss 3.1epss 0.00

    HCL BigFix Service Management is affected by a CORS Misconfiguration vulnerability due to improperly validated origin headers, which could allow an attacker to craft a malicious web page that interacts with the vulnerable application, enabling unauthorized access to protected…

  • CVE-2025-31975LowMay 6, 2026
    risk 0.17cvss 2.6epss 0.00

    HCL BigFix Service Management (SM) is affected by an Information Disclosure – Server Banner issue was identified. Exposed server banners may reveal software versions and system details, potentially aiding attackers in targeting known vulnerabilities.

  • CVE-2025-31957LowMay 6, 2026
    risk 0.17cvss 2.6epss 0.00

    HHCL BigFix Service Management (SM) is affected by a Cross‑Site Request Forgery (CSRF) vulnerability. This could lead to unauthorized changes or exposure of sensitive data.

Page 2 of 2