CVE-2025-31959

LOW

HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images.

Title source: cna
STIX 2.1

Description

HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. This could lead to confidentiality and privacy risks if sensitive location information is unintentionally shared. .

Scores

CVSS v3 3.5
EPSS 0.0003
EPSS Percentile 8.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1230
Status published
Products (2)
HCL Software/BigFix Service Management (SM) 23
hcltech/bigfix_service_management 23.0
Published May 06, 2026
Tracked Since May 06, 2026