VendorsHcltechbigfix_service_managementall versions
Vulnerabilities

Hcltech HCL Technologies BigFix Service Management (SM)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18CVEs
CVE-2025-31973
HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'
Published 2026-05-20 · Analyzed
9.8EPSS 0.002
CVE-2025-52613
HCL BigFix Service Management (SM) is affected by use of a vulnerable component
Published 2026-05-06 · Analyzed
8.8EPSS 0.002
CVE-2024-30151
HCL BigFix Service Management (SM) is susceptible to Broken Access Control Vulnerability
Published 2026-05-06 · Analyzed
8.3EPSS 0.002
CVE-2025-31958
HCL BigFix Service Management (SM) is susceptible to HTTP Request Smuggling
Published 2026-04-21 · Analyzed
8.2EPSS 0.002
CVE-2025-31976
HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials
Published 2026-05-06 · Analyzed
7.5EPSS 0.002
CVE-2025-31974
HCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-Only
Published 2026-05-06 · Analyzed
7.2EPSS 0.002
CVE-2025-31985
HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header
Published 2026-05-20 · Analyzed
6.5EPSS 0.002
CVE-2025-31982
HCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed directl
Published 2026-05-06 · Analyzed
6.5EPSS 0.002
CVE-2025-31977
A cryptographic weakness has been identified in the HCL BigFix Service Management (SM)
Published 2025-08-28 · Analyzed
6.5EPSS 0.001
CVE-2025-31972
HCL BigFix Service Management (SM) is affected by a Sensitive Information Exposure vulnerability
Published 2025-08-28 · Analyzed
6.5EPSS 0.001
CVE-2025-31957
HCL BigFix Service Management (SM) is affected by a Cross‑Site Request Forgery (CSRF) vulnerability.
Published 2026-05-06 · Analyzed
5.7EPSS 0.001
CVE-2025-31984
HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header
Published 2026-05-06 · Analyzed
5.4EPSS 0.001
CVE-2025-31960
HCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its reporting module
Published 2026-05-06 · Analyzed
5.3EPSS 0.002
CVE-2025-31975
HCL BigFix Service Management (SM) is affected by an Information Disclosure – Server Banner issue was identified.
Published 2026-05-06 · Analyzed
5.3EPSS 0.002
CVE-2025-31981
HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption
Published 2026-04-21 · Analyzed
5.3EPSS 0.001
CVE-2025-31978
HCL BigFix Service Management (SM) does not adequately sanitize or safely render
Published 2026-05-06 · Analyzed
4.6EPSS 0.001
CVE-2025-31983
HCL BigFix Service Management (SM) is affected by a security misconfiguration vulnerability due to CSP header
Published 2026-05-06 · Analyzed
4.6EPSS 0.001
CVE-2025-31959
HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images.
Published 2026-05-06 · Analyzed
3.5EPSS 0.001