CVE-2025-31959
low
CVSS v3
3.5
CVSS v2
—
VIR risk
3.5
Description
HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. This could lead to confidentiality and privacy risks if sensitive location information is unintentionally shared. .
Predictions
Exploit likelihood
45%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@hcl.com — https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0128144
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| hcltech | bigfix_service_management | 23.0 | |
References
CWEs
CWE-1230
Verify integrity in audit chain (admin only). AS-IS.