CVE-2025-31954

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/11/2025
Last modified:
07/11/2025

Description

HCL iAutomate v6.5.1 and v6.5.2 is susceptible to a sensitive information disclosure. An HTTP GET method is used to process a request and includes sensitive information in the query string of that request. An attacker could potentially access information or resources they were not intended to see.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hcltech:dryice_iautomate:6.5.1:*:*:*:*:*:*:*
cpe:2.3:a:hcltech:dryice_iautomate:6.5.2:*:*:*:*:*:*:*