---
id: CVE-2025-31982
title: >-
  HCL BigFix Service Management (SM) had directories that were not linked or
  publicly visible but could be accessed directly
summary: >-
  HCL BigFix Service Management (SM) had directories that were not linked or
  publicly visible but could be accessed directly. This could allow an increased
  risk of information disclosure or misuse of sensitive functionality.
severity: low
cvss: 3.7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:L'
cwe:
  - CWE-200
vendor: hcltech
product: bigfix_service_management
affected:
  - bigfix_service_management = 23.0
published: '2026-05-06'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T22:10:00.273'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-31982'
references:
  - url: >-
      https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0128144
    label: psirt@hcl.com
tags:
  - nvd
epss: 0.00153
epssPercentile: 0.03782
ingestedAt: '2026-09-30T22:27:27.782Z'
---

## Overview

HCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed directly. This could allow an increased risk of information disclosure or misuse of sensitive functionality.

## Affected

- `bigfix_service_management = 23.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
