Executive brief
HCL BigFix Service Management is a platform used by organizations to manage IT infrastructure and services. An authenticated attacker can exploit SQL injection flaws to extract sensitive system details from the database, and can manipulate requests to access personal profile data and personally identifiable information (PII) across different customer organizations, creating a significant risk of data breach and unauthorized exposure of confidential business and personal information.
Technical details
The vulnerability consists of two related flaws: (1) a SQL injection vulnerability that allows an authenticated attacker to inject malicious SQL commands into database queries, enabling extraction of sensitive system information, and (2) a cross-tenant data exposure flaw that permits manipulation of request values to access personal profile data and PII from users in different organizations. Both flaws require prior authentication but allow an attacker with valid credentials to move laterally across tenant boundaries and bypass data isolation controls. The attack vector is network-based, and the impact includes unauthorized data access and potential exfiltration of sensitive customer information. Patch availability is referenced via HCL support documentation.
Affected products
- HCL BigFix Service Management
Timeline
- 2026-09-18: disclosed