PT-2025-35107 · Hcl · Hcl Bigfix Sm

Published

2025-08-28

·

Updated

2025-08-28

·

CVE-2025-31972

CVSS v3.1
6.5
VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Name of the Vulnerable Software and Affected Versions:

HCL BigFix SM (affected versions not specified)

Description:

HCL BigFix SM is affected by a sensitive information exposure issue. Internal connections do not use TLS encryption, potentially allowing an attacker unauthorized access to sensitive data transmitted between internal components.

Recommendations:

At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2025-31972

Affected Products

Hcl Bigfix Sm