PT-2026-38085 · Hcl · Bigfix Service Management

Published

2026-05-06

·

Updated

2026-05-07

·

CVE-2025-31960

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions HCL BigFix Service Management (SM) (affected versions not specified)
Description Improper error handling within the reporting module leads to information exposure. Supplying an invalid or out-of-range value to the consumer company parameter during a report-viewing request triggers an unhandled exception.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Generation of Error Message Containing Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2025-31960

Affected Products

Bigfix Service Management