CVE-2021-27780
The software may be vulnerable to both Un-Auth XML interaction and unauthenticated device enrollment.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS probability
- 0.21%
- CWE
- CWE-112
- Published
- 2022-05-27
- Last modified
- 2026-03-13
Affected products
- HCL Software HCL BigFix Mobile / Modern Client Management
Weakness type
Related vulnerabilities
- CVE-2026-1190 — Org.keycloak/keycloak-services: keycloak saml brokering: response delay due to unchecked notonorafter in subjectconfirmationdata
- CVE-2023-40310 — Missing XML Validation vulnerability in SAP PowerDesigner Client BPMN2 import
- CVE-2022-28213 — When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform -...
- CVE-2021-1359 — Cisco Web Security Appliance Privilege Escalation Vulnerability
- CVE-2020-27282 — In Hamilton Medical AG,T1-Ventillator versions 2.2.3 and prior, an XML validation vulnerability in...
- CVE-2020-1975 — Missing XML Validation in PAN-OS Web Interface