CVE-2025-31960: Hcltech Bigfix Service Management

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

HCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its reporting module. It was observed that supplying an invalid or out-of-range value to the consumer_company parameter during a report-viewing request causes the application to trigger an unhandled exception.

Affected products

  • Hcltech Bigfix Service Management: version 23.0 only

Published 2026-05-06. Last modified 2026-10-07.