HCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its reporting module
CVE-2025-31960
5.3MEDIUM
What is CVE-2025-31960?
HCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its reporting module. It was observed that supplying an invalid or out-of-range value to the consumer_company parameter during a report-viewing request causes the application to trigger an unhandled exception.
Affected Version(s)
BigFix Service Management (SM) 23