CVE-2025-31972: HCL BigFix Service Management (SM) is affected by a Sensitive Information Exposure vulnerability
Published Aug 28, 2025
·Updated
HCL BigFix SM is affected by a Sensitive Information Exposure vulnerability where internal connections do not use TLS encryption which could allow an attacker unauthorized access to sensitive data transmitted between internal components.
Affected Software
2 affected components
HCL BigFix SM
hcltech Bigfix Service Management=23.0
Event History
Aug 28, 2025
CVE Published
via MITRE·04:50 PM
Data Sourced
via MITRE·04:50 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-31972?
CVE-2025-31972 has a medium severity rating due to the risk of sensitive information exposure.
2
How do I fix CVE-2025-31972?
To fix CVE-2025-31972, enable TLS encryption for all internal connections in HCL BigFix SM.
3
What type of information is exposed in CVE-2025-31972?
CVE-2025-31972 may expose sensitive data transmitted between internal components of HCL BigFix SM.
4
Who is affected by CVE-2025-31972?
CVE-2025-31972 affects users of HCL BigFix SM that do not encrypt internal connections.
5
What can an attacker do with the vulnerability in CVE-2025-31972?
An attacker could gain unauthorized access to sensitive information transmitted over internal connections exploited in CVE-2025-31972.