← Back

CVE-2025-31959

nvd nist
Published: May 6, 2026Modified: Jun 17, 2026

JSON object

Loading...
3.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
Exploitability: 2.1 / Impact: 1.4
Source: psirt@hcl.com (Secondary)

Description

HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. This could lead to confidentiality and privacy risks if sensitive location information is unintentionally shared. .

Affected (1)

1 product
Bigfix Service Management
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 23.0

Timeline

No history available yet.