Skip to main content

CVE-2025-31972: CWE-319 Cleartext Transmission of Sensitive Information in HCL Software BigFix Service Management (SM)

Medium
VulnerabilityCVE-2025-31972cvecve-2025-31972cwe-319
Published: Thu Aug 28 2025 (08/28/2025, 16:50:07 UTC)
Source: CVE Database V5
Vendor/Project: HCL Software
Product: BigFix Service Management (SM)

Description

HCL BigFix SM is affected by a Sensitive Information Exposure vulnerability where internal connections do not use TLS encryption which could allow an attacker unauthorized access to sensitive data transmitted between internal components.

Technical Details

Data Version
5.1
Assigner Short Name
HCL
Date Reserved
2025-04-01T18:46:26.620Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 68b08bb7ad5a09ad006e532e

Added to database: 8/28/2025, 5:02:47 PM

Last updated: 8/28/2025, 5:02:47 PM

Views: 1

Actions

Please log in to the Console to use AI analysis features.

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats