Security Misconfiguration in HCL BigFix Service Management
CVE-2025-31984
3.7LOW
What is CVE-2025-31984?
HCL BigFix Service Management is affected by a security misconfiguration due to a missing or improperly configured 'X-Content-Type-Options' header. This oversight can allow web browsers to perform MIME-type sniffing, which might result in malicious content being executed or interpreted incorrectly by users' browsers. Proper configuration of the X-Content-Type-Options header is essential to protect against such vulnerabilities and ensure safer web browsing experiences.
Affected Version(s)
BigFix Service Management (SM) 23