Executive brief
HCL BigFix Service Management is affected by a configuration issue where it utilizes outdated or insecure base software images. This product is used by organizations to manage IT services and infrastructure. Using obsolete base images can leave the environment exposed to older, well-known security flaws that could be used to compromise the system's integrity or availability.
Technical details
HCL BigFix Service Management (SM) contains a configuration vulnerability categorized as 'Insecure Use of Base Image Version'. The root cause is the deployment of the application using base images that are either outdated or contain known security weaknesses. An attacker with high privileges on the local system could potentially leverage vulnerabilities inherent in these underlying images to impact the confidentiality, integrity, or availability of the service. The attack vector is local, requiring high privileges and some level of user interaction. Users are advised to refer to HCL security bulletin KB0128144 for remediation steps and updated image versions.
Affected products
- HCL BigFix Service Management (SM)
Timeline
- 2026-05-20: advisory: Initial disclosure by HCL Software
- 2026-05-20: disclosed