CVE-2025-31959
3.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
Exploitability: 2.1 / Impact: 1.4
Source: psirt@hcl.com (Secondary)
Description
HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. This could lead to confidentiality and privacy risks if sensitive location information is unintentionally shared. .
Affected (1)
Products: Hcltech: Bigfix Service Management
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 23.0 |
References (1)
Source: psirt@hcl.com
Vendor Advisory
Timeline
No history available yet.