CVE-2025-31982: Hcltech Bigfix Service Management

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

HCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed directly. This could allow an increased risk of information disclosure or misuse of sensitive functionality.

Affected products

  • Hcltech Bigfix Service Management: version 23.0 only

Published 2026-05-06. Last modified 2026-10-07.