PT-2026-37630 · Hhcl · Bigfix Service Management

Published

2026-05-06

·

Updated

2026-05-06

·

CVE-2025-31957

CVSS v3.1

5.7

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions HHCL BigFix Service Management (SM) (affected versions not specified)
Description HHCL BigFix Service Management (SM) is affected by a Cross-Site Request Forgery (CSRF) issue, which is a flaw that allows an attacker to induce a user's browser to perform unwanted actions on a different website where the user is authenticated. This could lead to unauthorized changes or exposure of sensitive data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-31957

Affected Products

Bigfix Service Management