CVE-2025-31982

LOW

HCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed directl

Title source: cna
STIX 2.1

Description

HCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed directly. This could allow an increased risk of information disclosure or misuse of sensitive functionality.

Scores

CVSS v3 3.7
EPSS 0.0003
EPSS Percentile 9.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (2)
HCL Software/BigFix Service Management (SM) 23
hcltech/bigfix_service_management 23.0
Published May 06, 2026
Tracked Since May 06, 2026