CVE-2025-31960
⚪ Do wiadomości
Niewłaściwe zarządzanie błędami w HCL BigFix SM ujawnia informacje przez nieobsługiwane wyjątki.
CVSS
5.3
EPSS
0.2%
Exploit
none
Vendor
hcltech
Opis źródłowy (NVD)
HCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its reporting module. It was observed that supplying an invalid or out-of-range value to the consumer_company parameter during a report-viewing request causes the application to trigger an unhandled exception.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 5.3 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.2% |
| Opublikowano (NVD) | 2026-05-06 19:16:35 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-07 09:10:00 UTC |
Referencje