Security Misconfiguration in HCL BigFix Service Management
CVE-2025-31984

3.7LOW

Key Information:

Vendor
CVE Published:
6 May 2026

What is CVE-2025-31984?

HCL BigFix Service Management is affected by a security misconfiguration due to a missing or improperly configured 'X-Content-Type-Options' header. This oversight can allow web browsers to perform MIME-type sniffing, which might result in malicious content being executed or interpreted incorrectly by users' browsers. Proper configuration of the X-Content-Type-Options header is essential to protect against such vulnerabilities and ensure safer web browsing experiences.

Affected Version(s)

BigFix Service Management (SM) 23

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.