HIGHCVE-2026-21821Published Modified CNA HCL
CVE-2026-21821: HCL BigFix SCM Reporting is affected by vulnerabilities in jQuery
The HCL BigFix SCM Reporting site contains an outdated and unsupported version of the jQuery 1.x library. Since jQuery 1.x has reached end-of-life and no longer receives security updates, it may expose the application to publicly known security weaknesses and increase the risk of client-side attacks such as Cross-Site Scripting (XSS) or manipulation through vulnerable third-party components.
Metrics
- CVSS v3.1
- 8.3
- Severity
- HIGH
- Fixed in
- —
- Affected Products
- 1
Affected packages
- HCLSoftware / BigFix SCM Reporting11.0.5
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:HReferences