CVE-2025-31954
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/11/2025
Last modified:
07/11/2025
Description
HCL iAutomate v6.5.1 and v6.5.2 is susceptible to a sensitive information disclosure. An HTTP GET method is used to process a request and includes sensitive information in the query string of that request. An attacker could potentially access information or resources they were not intended to see.
Impact
Base Score 3.x
5.40
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:hcltech:dryice_iautomate:6.5.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:hcltech:dryice_iautomate:6.5.2:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



