PatchSiren

HCL Software CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW HCL Software CVE published 2026-09-18

CVE-2026-56597

CVE-2026-56597 is a Sensitive Information Leakage vulnerability affecting HCL BigFix Service Management. An unauthenticated attacker could extract internal IP addresses from application responses, enabling them to map the underlying network topology and identify potential internal targets. This vulnerability allows defenders to assess exposure and prioritize mitigation, especially in sensitive environment [truncated]

LOW HCL Software CVE published 2026-09-18

CVE-2026-56595

CVE-2026-56595 is a CORS Misconfiguration vulnerability in HCL BigFix Service Management. The vulnerability is due to improperly validated origin headers, which could allow an attacker to craft a malicious web page that interacts with the vulnerable application, enabling unauthorized access to protected resources and restricted APIs on behalf of a victim. The CVSS score is 3.1, indicating a low severity. [truncated]

MEDIUM HCL Software CVE published 2026-09-18

CVE-2026-56592

CVE-2026-56592 is an Improper Authentication validation vulnerability in HCL BigFix Service Management. This vulnerability allows unauthenticated attackers to execute sustained brute-force attacks against the login interface, potentially resulting in unauthorized system access. The vulnerability is related to inadequate account lockouts. Defenders should assess exposure, especially for publicly accessible [truncated]

MEDIUM HCL Software CVE published 2026-09-18

CVE-2026-56590

CVE-2026-56590 is a medium-severity Unrestricted File Upload vulnerability affecting HCL BigFix Service Management. An unauthenticated attacker could potentially upload and execute malicious payloads, leading to a complete server compromise. The CVE record was published on 2026-09-18T09:16:41.663Z and has not been modified since then. The NVD entry is currently Undergoing Analysis.

MEDIUM HCL Software CVE published 2026-09-18

CVE-2026-21848

CVE-2026-21848 is a Security Misconfiguration vulnerability in HCL BigFix Service Management that could allow an authenticated attacker to view restricted data elements across tenant boundaries. The CVE record was published on 2026-09-18T09:16:40.117Z and has not been modified since then. The NVD entry is currently Undergoing Analysis. This vulnerability affects HCL BigFix Service Management deployments, [truncated]

MEDIUM HCL Software CVE published 2026-09-18

CVE-2026-21822

A Path Traversal vulnerability was found in HCLSoftware AppScan 360°'s ASReportService component. This issue allows an authenticated attacker to read or write files outside the intended directory, potentially enabling file system structure inspection or unauthorized file modification within the application's directory scope. The vulnerability impacts the confidentiality and integrity of the affected syste [truncated]

HIGH HCL Software CVE published 2026-09-18

CVE-2026-67103

HCL BigFix Service Management is affected by a Cross-Site Scripting (XSS) vulnerability. An attacker could inject unsanitized malicious scripts that execute in a victim's browser, enabling session hijacking, account takeover, and unauthorized actions. The vulnerability exists due to insufficient input validation and sanitization of user-supplied input. Successful exploitation could allow an attacker to pe [truncated]

HIGH HCL Software CVE published 2026-09-18

CVE-2026-67102

A high-severity Broken Access Control vulnerability in HCL BigFix Service Management could allow a low-privileged user to gain unauthorized access to administrative screens and functions reserved for higher-privileged roles. This vulnerability, tracked as CVE-2026-67102, could enable low-privileged users to access sensitive areas of the system, potentially leading to unauthorized actions. Defenders should [truncated]

CRITICAL HCL Software CVE published 2026-09-18

CVE-2026-67101

A Server-Side Request Forgery (SSRF) vulnerability exists in HCL BigFix Service Management's search functionality. This could allow an attacker to force the application server to send requests to internal systems not accessible from the internet. The vulnerability has a CVSS score of 9.3, indicating critical severity. Defenders should assess exposure and prioritize remediation. Limited information is avai [truncated]

CRITICAL HCL Software CVE published 2026-09-18

CVE-2026-67100

CVE-2026-67100 is a critical SQL Injection and Cross-Tenant Data Exposure vulnerability in HCL BigFix Service Management. An authenticated attacker can inject database commands to extract sensitive system details and manipulate request values to gain unauthorized access to full personal profile data and PII across different organizations. Defenders responsible for authentication, data protection, and vuln [truncated]

LOW HCL Software CVE published 2026-09-07

CVE-2025-52657

A potential Denial of Service (DoS) vulnerability was found in HCL MyXalytics. The vulnerability allows users to input data without any restriction on the number of characters, which can impact system performance or availability. This issue could lead to system performance degradation or availability concerns if exploited. Defenders responsible for HCL MyXalytics deployments should assess exposure and pri [truncated]

LOW HCL Software CVE published 2026-09-07

CVE-2025-52652

CVE-2025-52652 debrief based on the supplied source corpus. The vulnerability is a Content Spoofing Vulnerability in HCL MyXalytics, which may allow an attacker to manipulate displayed content, potentially leading to phishing or data theft. Defenders responsible for HCL MyXalytics deployments should assess exposure and prioritize verification. The CVE record and NVD entry provide limited information about [truncated]

LOW HCL Software CVE published 2026-09-07

CVE-2025-52651

HCL MyXalytics was affected by an Improper Input Validation Vulnerability. The CVE record, published on 2026-09-07T11:17:19.503Z, indicates that malicious or unexpected data could cause unintended system behavior or security issues. Defenders should assess exposure and verify system configurations. The vulnerability allows malicious input to cause system issues, impacting HCL MyXalytics systems. Verificat [truncated]

LOW HCL Software CVE published 2026-08-25

CVE-2026-21758

CVE-2026-21758 is an information disclosure vulnerability affecting HCL Hive. The CVE record was published on 2026-08-25T11:16:51.917Z and has not been modified since then. The NVD entry is currently Deferred. Defenders should assess the vulnerability's impact and prioritize remediation based on the information provided in the CVE record and NVD detail page. The vulnerability could lead to an attacker gat [truncated]

MEDIUM HCL Software CVE published 2026-08-25

CVE-2026-21754

CVE-2026-21754 is a medium-severity vulnerability affecting HCL Hive, which could lead to unauthorized lateral movement, container breakout, and sensitive data exposure within internal communications. The CVE record was published on 2026-08-25T11:16:51.797Z and has not been modified since then. Defenders responsible for HCL Hive installations should assess exposure and prioritize patching to prevent poten [truncated]

MEDIUM HCL Software CVE published 2026-08-25

CVE-2026-21753

HCL Hive's weak software supply chain governance could lead to the inclusion of vulnerable, unmaintained, or malicious third-party dependencies within the application environment. This vulnerability affects defenders responsible for HCL Hive environments, security teams, and developers, who should assess exposure and prioritize verification of third-party dependencies. The CVE record and NVD entry provide [truncated]

MEDIUM HCL Software CVE published 2026-08-20

CVE-2025-62306

CVE-2025-62306 debrief based on the supplied source corpus. HCL IntelliOps Event Management (IEM) is affected by information omission, impacting auditability and observability of workflows. Insufficient logging could hinder incident response if an attacker gains access to the application. Roles responsible for IEM administration, security, and incident response should assess exposure and verify logging co [truncated]

MEDIUM HCL Software CVE published 2026-08-20

CVE-2025-62300

A race condition in HCL IntelliOps Event Management (IEM) can cause unpredictable behavior when an attacker modifies a resource within a specific timing window. This vulnerability, tracked as CVE-2025-62300, affects IEM deployments and requires verification of potential exposure and impact assessment. Defenders should prioritize verifying IEM deployments for potential exposure and assessing the impact of [truncated]

MEDIUM HCL Software CVE published 2026-08-20

CVE-2025-62299

CVE-2025-62299 is a least privileges violation affecting HCL IntelliOps Event Management (IEM). An attacker could access a resource with elevated privilege not accessible with their original privileges. The CVSS score is 6.6, with a severity of MEDIUM. This vulnerability could allow attackers to escalate privileges and gain unauthorized access to sensitive resources. Defenders should prioritize verifying [truncated]

MEDIUM HCL Software CVE published 2026-08-20

CVE-2025-62307

CVE-2025-62307 debrief based on the supplied source corpus. The CVE record was published on 2026-08-20T12:16:32.150Z and has not been modified since then. This medium-severity vulnerability affects HCL IntelliOps Event Management (IEM) and is caused by insufficient logging, which weakens accountability, obscures attack detection, and enables privilege probing. Defenders and security teams responsible for [truncated]

LOW HCL Software CVE published 2026-08-03

CVE-2026-56608

The HCL iControl application, used for managing and monitoring HCL products, is affected by a Missing Access Control vulnerability. This vulnerability class allows users to access or view administrator-level functionalities without appropriate authorization, potentially leading to unauthorized access attempts. The CVE record was published on 2026-08-03T13:18:52.257Z and has not been modified since then. O [truncated]

LOW HCL Software CVE published 2026-07-31

CVE-2026-56570

The HCL iControl system has an Auto complete Enabled vulnerability, potentially exposing sensitive information such as valid usernames, email addresses, and account identifiers in shared environments. This vulnerability was published on 2026-07-31T16:17:07.637Z and has not been modified since then. Administrators and users of HCL iControl systems, especially those accessed from shared environments, should [truncated]

MEDIUM HCL Software CVE published 2026-07-31

CVE-2026-56569

HCL iControl was affected by Sensitive Data Exposure vulnerabilities due to improper web server or application hardening. This could lead to the public exposure of internal configuration files. Administrators and users of HCL iControl, as well as organizations relying on this software for critical operations, should review and apply vendor remediation if available. They should also verify and update affec [truncated]

MEDIUM HCL Software CVE published 2026-07-31

CVE-2026-56567

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record for CVE-2026-56567 was published on 2026-07-31T16:17:07.290Z and has not been modified since then. HCL iControl v4.3.0 is affected by Security Misconfiguration vulnerabilities due to improper web server or application hardening, leading to public exposure of internal configuration files. Organizations using HCL iControl v4. [truncated]

CRITICAL HCL Software CVE published 2026-07-17

CVE-2024-23564

CVE-2024-23564 is a critical business logic vulnerability in HCL Aftermarket EPC that allows a non-valid user to obtain passwords from the server and redirect them to their own email address by manipulating the server's response. The application includes checks in the initial requests to verify the validity of the provided UserId, but similar validation is not applied to Email requests when sending passwo [truncated]

MEDIUM HCL Software CVE published 2026-07-16

CVE-2026-56456

HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability. The application dashboard inadvertently leaks sensitive information regarding its internal file structure and directory paths through unhandled error messages, system logs, or debugging output. This vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. Security teams and administrators responsible for HCL [truncated]

MEDIUM HCL Software CVE published 2026-07-16

CVE-2026-56455

HCL DFXAnalytics is affected by a Buffer Overflow vulnerability that can lead to a Denial of Service (DoS). The application fails to properly validate input sizes, allowing an attacker to pass an excessive amount of information into a memory container, which can cause the system to crash or become unresponsive. This vulnerability has a CVSS score of 5.3 and is classified as a Medium priority due to its po [truncated]

MEDIUM HCL Software CVE published 2026-07-16

CVE-2026-56454

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-16T14:16:54.643Z and has not been modified since then. The NVD entry is currently Undergoing Analysis. HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1. These legacy protocols contain numerous cryptographic design flaws that expose data to int [truncated]

MEDIUM HCL Software CVE published 2026-07-16

CVE-2026-56453

CVE-2026-56453 is an Account Takeover via Response Manipulation vulnerability affecting HCL DFXAnalytics. A remote attacker can intercept and alter server HTTP responses before they reach the client application, allowing them to manipulate authentication or authorization logic to bypass controls and gain unauthorized access to targeted user accounts. This type of vulnerability typically allows attackers t [truncated]

LOW HCL Software CVE published 2026-07-16

CVE-2026-35143

The CVE record for CVE-2026-35143 was published on 2026-07-16T14:16:50.973Z and has not been modified since then. The NVD entry is currently Undergoing Analysis. This CVE is related to a Missing SameSite Attribute vulnerability in HCL DFXAnalytics, which could allow Cross-Site Request Forgery (CSRF) attacks if additional mitigations are not implemented.