CVE-2025-31983: HCL BigFix Service Management (SM) is affected by a security misconfiguration vulnerability due to CSP header
HCL BigFix Service Management (SM) is affected by a security misconfiguration vulnerability due to CSP header. This could allow attackers to inject malicious scripts increasing the risk of cross-site scripting (XSS) and potential exposure of sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31983?
CVE-2025-31983 has a critical severity level due to its potential to allow script injection through security misconfiguration.
How do I fix CVE-2025-31983?
To fix CVE-2025-31983, ensure that the Content Security Policy (CSP) headers are properly configured to prevent unauthorized script execution.
What software is affected by CVE-2025-31983?
CVE-2025-31983 affects HCL BigFix Service Management.
What kind of attack does CVE-2025-31983 enable?
CVE-2025-31983 enables attackers to inject malicious scripts into the application, increasing the risk of cross-site scripting (XSS) attacks.
Is there a workaround for CVE-2025-31983?
A recommended workaround for CVE-2025-31983 is to review and adjust the current CSP settings until a complete patch can be applied.