Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

BigFix Service Management (SM) — Vulnerabilities & Security Advisories 19

All 19 CVE vulnerabilities found in BigFix Service Management (SM), with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security weaknesses affecting BigFix Service Management (SM), a service management solution developed by HCL Software. It collects documented security vulnerabilities for this specific product, covering advisories published from 2018 through 2024. Users can track the vendor’s security advisories, analyze the progression of specific weakness classes such as buffer overflows and injection flaws, and review the full vulnerability history of the product to assess its historical security posture. The collection excludes unverified or disputed reports, focusing strictly on confirmed issues with available mitigation strategies. No individual CVE identifiers are listed here; instead, the data is organized by vulnerability type and release timeframe, enabling a high-level view of the product’s security evolution over the specified period.

Vendor: HCL Software

CVE ID Title CVSS Severity Published
CVE-2025-31985 HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header CWE-200 3.7 Low 2026-05-20
CVE-2025-31973 HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version' CWE-1395 4.0 Medium 2026-05-20
CVE-2024-30151 HCL BigFix Service Management (SM) is susceptible to Broken Access Control Vulnerability CWE-532 8.3 High 2026-05-06
CVE-2025-31960 HCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its reporting module CWE-209 5.3 Medium 2026-05-06
CVE-2025-31974 HCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-Only CWE-1188 3.9 Low 2026-05-06
CVE-2025-31975 HCL BigFix Service Management (SM) is affected by an Information Disclosure – Server Banner issue was identified. CWE-200 2.6 Low 2026-05-06
CVE-2025-52613 HCL BigFix Service Management (SM) is affected by use of a vulnerable component CWE-200 4.6 Medium 2026-05-06
CVE-2025-31976 HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials CWE-200 4.8 Medium 2026-05-06
CVE-2025-31978 HCL BigFix Service Management (SM) does not adequately sanitize or safely render CWE-201 4.6 Medium 2026-05-06
CVE-2025-31959 HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. CWE-1230 3.5 Low 2026-05-06
CVE-2025-31982 HCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed directl CWE-200 3.7 Low 2026-05-06
CVE-2025-31984 HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header CWE-200 3.7 Low 2026-05-06
CVE-2025-31983 HCL BigFix Service Management (SM) is affected by a security misconfiguration vulnerability due to CSP header CWE-358 3.7 Low 2026-05-06
CVE-2025-31957 HCL BigFix Service Management (SM) is affected by a Cross‑Site Request Forgery (CSRF) vulnerability. CWE-352 2.6 Low 2026-05-06
CVE-2025-31981 HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption CWE-319 5.3 Medium 2026-04-21
CVE-2025-31958 HCL BigFix Service Management (SM) is susceptible to HTTP Request Smuggling CWE-444 3.7 Low 2026-04-21
CVE-2025-31979 A File Upload Validation Bypass vulnerability has been identified in the HCL BigFix Service Management (SM) CWE-434 5.4 Medium 2025-08-28
CVE-2025-31977 A cryptographic weakness has been identified in the HCL BigFix Service Management (SM) CWE-311 5.3 Medium 2025-08-28
CVE-2025-31972 HCL BigFix Service Management (SM) is affected by a Sensitive Information Exposure vulnerability CWE-319 6.5 Medium 2025-08-28

All 19 known CVE vulnerabilities affecting BigFix Service Management (SM) with full Chinese analysis, references, and POCs where available.