CVE-2025-31972: CWE-319 Cleartext Transmission of Sensitive Information in HCL Software BigFix Service Management (SM)
HCL BigFix SM is affected by a Sensitive Information Exposure vulnerability where internal connections do not use TLS encryption which could allow an attacker unauthorized access to sensitive data transmitted between internal components.
CVE-2025-31972: CWE-319 Cleartext Transmission of Sensitive Information in HCL Software BigFix Service Management (SM)
Description
HCL BigFix SM is affected by a Sensitive Information Exposure vulnerability where internal connections do not use TLS encryption which could allow an attacker unauthorized access to sensitive data transmitted between internal components.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- HCL
- Date Reserved
- 2025-04-01T18:46:26.620Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 68b08bb7ad5a09ad006e532e
Added to database: 8/28/2025, 5:02:47 PM
Last updated: 8/28/2025, 5:02:47 PM
Views: 1
Related Threats
CVE-2025-58335: CWE-356 in JetBrains Junie
MediumCVE-2025-58334: CWE-862 in JetBrains IDE Services
HighCVE-2025-2950: CWE-644 Improper Neutralization of HTTP Headers for Scripting Syntax
MediumCVE-2025-57819: CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in FreePBX security-reporting
CriticalCVE-2025-25010: CWE-863 Incorrect Authorization in Elastic Kibana
MediumActions
External Links
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.