VYPR

BigFix Quantum Risk Analyzer

by HCL Software

CVEs (4)

  • CVE-2026-21810MedAug 26, 2026
    risk 0.29cvss 4.4epss

    HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and a lack of binary integrity which could allow an attacker to obtain sensitive information or modify the binary.

  • CVE-2026-21808MedAug 26, 2026
    risk 0.27cvss 4.1epss

    HCL BigFix Quantum Risk Analyzer generates highly detailed logging information by default which increases the risk of sensitive data leakage and can provide an attacker with internal application logic and architectural details.

  • CVE-2026-21807LowAug 26, 2026
    risk 0.25cvss 3.9epss

    HCL BigFix Quantum Risk Analyzer binary lacks several critical, industry-standard hardening protections that could allow an attacker to cause a stack-based buffer overflow.

  • CVE-2026-21809LowAug 26, 2026
    risk 0.25cvss 3.9epss

    HCL BigFix Quantum Risk Analyzer has a certain validation process that provides overly descriptive error messages when it encounters malformed input which can allow an attacker to conduct more efficient reconnaissance and fine-tune automated fuzzing tools to produce valid input.