Description
HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerability. A flaw in a component's input handling was identified that could permit unauthorized command execution.
Problem types
CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
CWE-451:User Interface (UI) Misrepresentation of Critical Information
CWE-351 Insufficient type distinction
Product status
11.2
References
support.hcl-software.com/...rticle&sysparm_article=KB0130444