CVE-2025-31960
Information Exposure in HCL BigFix Service Management
Publication date: 2026-05-06
Last updated on: 2026-05-06
Assigner: HCL Software
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| hcl | bigfix_service_management | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-209 | The product generates an error message that includes sensitive information about its environment, users, or associated data. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
HCL BigFix Service Management (SM) has a vulnerability related to improper error handling in its reporting module. Specifically, when an invalid or out-of-range value is provided to the consumer_company parameter during a report-viewing request, the application triggers an unhandled exception.
How can this vulnerability impact me? :
This vulnerability can lead to information exposure because the improper error handling may reveal sensitive details when an unhandled exception occurs. The CVSS score indicates a low to moderate impact on confidentiality, with no impact on integrity or availability.