CVE-2025-31960
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: psirt@hcl.com (Secondary)
Description
HCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its reporting module. It was observed that supplying an invalid or out-of-range value to the consumer_company parameter during a report-viewing request causes the application to trigger an unhandled exception.
Affected (1)
Products: Hcltech: Bigfix Service Management
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 23.0 |
References (1)
Source: psirt@hcl.com
Vendor Advisory
Timeline
No history available yet.