CVE-2025-31959: HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images.
HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. This could lead to confidentiality and privacy risks if sensitive location information is unintentionally shared. .
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31959?
CVE-2025-31959 has been classified as a medium severity vulnerability due to potential exposure of sensitive location information.
How do I fix CVE-2025-31959?
The fix for CVE-2025-31959 involves updating to the latest version of HCL BigFix Service Management that addresses the EXIF metadata stripping issue.
What are the risks associated with CVE-2025-31959?
CVE-2025-31959 presents risks related to confidentiality and privacy, as it may expose sensitive location data embedded in uploaded images.
Which versions of HCL BigFix Service Management are affected by CVE-2025-31959?
CVE-2025-31959 affects all versions of HCL BigFix Service Management that do not implement proper EXIF metadata handling.
Is there a patch available for CVE-2025-31959?
Yes, a patch is available to resolve the EXIF metadata stripping vulnerability in HCL BigFix Service Management.