Executive brief
HCL BigFix Service Management is an IT operations and service management platform used to monitor and manage enterprise systems. A Cross-Site Scripting (XSS) vulnerability allows attackers to inject malicious scripts that execute in users' browsers, enabling session hijacking, account takeover, and unauthorized actions performed on behalf of legitimate users.
Technical details
This is a Cross-Site Scripting (XSS) vulnerability in HCL BigFix Service Management caused by insufficient input sanitization. The vulnerability allows attackers to inject unsanitized malicious scripts that execute within the context of a victim's browser session. Exploitation can lead to session hijacking, account takeover, and unauthorized administrative actions. The vulnerability is network-accessible and likely requires user interaction (e.g., clicking a malicious link). A patch or update should be available from HCL Software.
Affected products
- HCL BigFix Service Management
Timeline
- 2026-09-18: disclosed