Executive brief
HCL BigFix Quantum Risk Analyzer is a risk assessment and compliance management tool used to identify and manage security vulnerabilities across IT infrastructure. By default, the application generates highly detailed logs that expose sensitive information including internal application logic, architectural details, and potentially confidential business data—creating a significant risk if logs are accessed by unauthorized parties or attackers.
Technical details
This vulnerability is an information disclosure issue caused by overly verbose logging enabled by default in HCL BigFix Quantum Risk Analyzer. The application logs sensitive details about its internal architecture, application logic, and operational data without adequate filtering or suppression. An attacker with access to logs (via misconfigured storage, unauthorized file access, or log aggregation systems) can extract architectural knowledge and sensitive information to facilitate further attacks. There are no preconditions for access beyond obtaining the log files themselves. Patches or configuration changes to disable verbose logging by default are expected to be available from HCL.
Affected products
- HCL BigFix Quantum Risk Analyzer
Timeline
- 2026-08-26: disclosed