Information Exposure Vulnerability in HCL BigFix Service Management
CVE-2025-31960
5.3MEDIUM
What is CVE-2025-31960?
HCL BigFix Service Management is affected by a vulnerability that arises due to improper error handling in its reporting module. When an invalid or out-of-range value is submitted to the consumer_company parameter during report viewing, the application trigger an unhandled exception, potentially exposing sensitive information. This exposure could allow unauthorized access to system details, presenting a significant security risk for affected deployments.
Affected Version(s)
BigFix Service Management (SM) 23