CVE-2026-21821
HIGH
8,3
Source: [email protected]
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: required
Scope: changed
Confidentiality: high
Integrity: high
Availability: high
Description
AI Translation Available
The HCL BigFix SCM Reporting site contains an outdated and unsupported version of the jQuery 1.x library. Since jQuery 1.x has reached end-of-life and no longer receives security updates, it may expose the application to publicly known security weaknesses and increase the risk of client-side attacks such as Cross-Site Scripting (XSS) or manipulation through vulnerable third-party components.
1104
Use of Unmaintained Third Party Components
IncompleteCommon Consequences
Security Scopes Affected:
Other
Potential Impacts:
Reduce Maintainability
Varies By Context
Applicable Platforms
Technologies:
ICS/OT, Not Technology-Specific
https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0130744