216.73.217.22

CVE-2025-31985

· Published 20/05/2026 12:16 · Modified 20/05/2026 19:09

Labels: CVE-2025-31985 2026-05-20CVE-2025-31985CWE-200NVD-CWE-noinfo[email protected]

Essential information

Published
20/05/2026 12:16
Modified
20/05/2026 19:09
Author
Creator
CVSS
3.7 LOW (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:L

CVSS metrics

Description

HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header. This could allow browsers to perform MIME-type sniffing, potentially causing malicious content to be interpreted and executed incorrectly.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
hcltech / bigfix service management cpe:2.3:a:hcltech:bigfix_service_management:23.0:*:*:*:*:*:*:*

References