CVE-2025-31983
Received Received - Intake
CSP Header Misconfiguration in HCL BigFix Service Management Leads to XSS

Publication date: 2026-05-06

Last updated on: 2026-05-06

Assigner: HCL Software

Description
HCL BigFix Service Management (SM) is affected by a security misconfiguration vulnerability due to CSP header. This could allow attackers to inject malicious scripts increasing the risk of cross-site scripting (XSS) and potential exposure of sensitive information.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-06
Last Modified
2026-05-06
Generated
2026-05-07
AI Q&A
2026-05-06
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
hcl bigfix_service_management *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-358 The product does not implement or incorrectly implements one or more security-relevant checks as specified by the design of a standardized algorithm, protocol, or technique.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

The vulnerability in HCL BigFix Service Management (SM) is caused by a security misconfiguration related to the Content Security Policy (CSP) header.

This misconfiguration could allow attackers to inject malicious scripts into the application, which increases the risk of cross-site scripting (XSS) attacks.

Such XSS attacks can potentially expose sensitive information to unauthorized parties.


How can this vulnerability impact me? :

This vulnerability can impact you by allowing attackers to perform cross-site scripting (XSS) attacks.

  • Attackers may inject malicious scripts that run in the context of your application.
  • This can lead to the exposure of sensitive information.
  • The CVSS score indicates a low to medium severity with potential limited impact on confidentiality and availability.

How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:

The vulnerability in HCL BigFix Service Management (SM) involves a security misconfiguration related to the Content Security Policy (CSP) header, which could allow attackers to inject malicious scripts and increase the risk of cross-site scripting (XSS). This type of vulnerability can potentially lead to exposure of sensitive information.

Exposure of sensitive information due to XSS vulnerabilities can impact compliance with common standards and regulations such as GDPR and HIPAA, which require protection of personal and sensitive data. However, the provided information does not explicitly detail the direct compliance impact or specific regulatory implications.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart