CVE-2026-21809
3.9
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L
Summary
HCL BigFix Quantum Risk Analyzer has a certain validation process that provides overly descriptive error messages when it encounters malformed input which can allow an attacker to conduct more efficient reconnaissance and fine-tune automated fuzzing tools to produce valid input.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| HCLSoftware | BigFix Quantum Risk Analyzer | 2.0.1.47 | affected |
Weaknesses
- CWE-209: CWE-209 Generation of error message containing sensitive information
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.