HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. which could allow an authenticated attacker to inject database commands to extract sensitive system details, as well as manipulate request values to gain unauthorized access to full personal profile data and PII across different organizations.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 18 Sep 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. which could allow an authenticated attacker to inject database commands to extract sensitive system details, as well as manipulate request values to gain unauthorized access to full personal profile data and PII across different organizations. | |
| Title | HCL BigFix Service Management is affected by multiple security vulnerabilities. | |
| Weaknesses | CWE-200 CWE-89 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: HCL
Published:
Updated: 2026-09-18T07:53:02.676Z
Reserved: 2026-07-28T13:24:18.240Z
Link: CVE-2026-67100
No data.
Status : Awaiting Analysis
Published: 2026-09-18T08:17:00.603
Modified: 2026-09-18T13:44:57.517
Link: CVE-2026-67100
No data.
OpenCVE Enrichment
No data.