CVE-2025-31959

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
06/05/2026
Last modified:
07/05/2026

Description

HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. This could lead to confidentiality and privacy risks if sensitive location information is unintentionally shared. .

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hcltech:bigfix_service_management:23.0:*:*:*:*:*:*:*