CVE-2025-31960
MEDIUMHCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its reporting module
Title source: cnaDescription
HCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its reporting module. It was observed that supplying an invalid or out-of-range value to the consumer_company parameter during a report-viewing request causes the application to trigger an unhandled exception.
References (1)
Core 1
Scores
CVSS v3
5.3
EPSS
0.0004
EPSS Percentile
11.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-209
Status
published
Products (2)
HCL/BigFix Service Management (SM)
23
hcltech/bigfix_service_management
23.0
Published
May 06, 2026
Tracked Since
May 07, 2026