CVE-2025-31982 PUBLISHED

HCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed directl

Assigner: HCL
Reserved: 01.04.2025 Published: 06.05.2026 Updated: 06.05.2026

HCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed directly. This could allow an increased risk of information disclosure or misuse of sensitive functionality.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:L
CVSS Score: 3.7

Product Status

Vendor HCL Software
Product BigFix Service Management (SM)
Versions Default: unaffected
  • Version 23 is affected

References

Problem Types

  • CWE-200: xposure of Sensitive Information to an Unauthorized Actor CWE