CVE-2025-31960
Awaiting Analysis Awaiting Analysis - Queue
Information Exposure in HCL BigFix Service Management

Publication date: 2026-05-06

Last updated on: 2026-05-06

Assigner: HCL Software

Description
HCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its reporting module. It was observed that supplying an invalid or out-of-range value to the consumer_company parameter during a report-viewing request causes the application to trigger an unhandled exception.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-06
Last Modified
2026-05-06
Generated
2026-05-07
AI Q&A
2026-05-06
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
hcl bigfix_service_management *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-209 The product generates an error message that includes sensitive information about its environment, users, or associated data.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

HCL BigFix Service Management (SM) has a vulnerability related to improper error handling in its reporting module. Specifically, when an invalid or out-of-range value is provided to the consumer_company parameter during a report-viewing request, the application triggers an unhandled exception.


How can this vulnerability impact me? :

This vulnerability can lead to information exposure because the improper error handling may reveal sensitive details when an unhandled exception occurs. The CVSS score indicates a low to moderate impact on confidentiality, with no impact on integrity or availability.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart