HCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed directl
8Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 3.7epss 0.2%
exploitation probability
0.2%top 95% of all CVEs
observed exploitation
nono source reports it
HCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed directly. This could allow an increased risk of information disclosure or misuse of sensitive functionality.
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:L
Affected products
HCL Software · BigFix Service Management (SM)