Junglewise Threat Intelligence

CVE-2025-62338: HCL BigFix Cloud Lifecycle Management information exposure via lack of input validation

CVE-2025-62338 · Severity: low · CVSS 3.3 · Published 2026-06-04

Vendors: HCL.

Executive brief

HCL BigFix Cloud Lifecycle Management, a tool used for managing cloud infrastructure, is affected by a security flaw where it fails to properly validate user input. This could allow a local user to gain unauthorized access to sensitive information. While the risk is considered low, it could lead to the exposure of data that should otherwise be protected.

Technical details

HCL BigFix Cloud Lifecycle Management contains an information exposure vulnerability due to insufficient input validation. An attacker with local access and low privileges can exploit this flaw to gain unauthorized access to sensitive data. The vulnerability is categorized as a low-severity issue with a CVSS score of 3.3, primarily impacting confidentiality. Users are advised to refer to HCL security bulletin KB0130802 for remediation steps and patch information.

Affected products

  • HCL BigFix Cloud Lifecycle Management

Timeline

  • 2026-06-04: disclosed
  • 2026-06-04: advisory: HCL published security bulletin KB0130802

References