Bigfix service management (sm)
This hub aggregates every CVE we track for Bigfix service management (sm), a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
19
CVEs tracked
0
Critical
1
High
0
In CISA KEV
Severity distribution
LOW9MEDIUM9HIGH1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
3
0
0
0
0
0
0
0
2
14
0
0
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Bigfix service management (sm).
- CVE-2025-31985HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header3.7
- CVE-2025-31973HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'4.0
- CVE-2024-30151HCL BigFix Service Management (SM) is susceptible to Broken Access Control Vulnerability8.3
- CVE-2025-31960HCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its reporting module5.3
- CVE-2025-31974HCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-Only3.9
- CVE-2025-31975HCL BigFix Service Management (SM) is affected by an Information Disclosure – Server Banner issue was identified.2.6
- CVE-2025-52613HCL BigFix Service Management (SM) is affected by use of a vulnerable component4.6
- CVE-2025-31976HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials4.8
- CVE-2025-31978HCL BigFix Service Management (SM) does not adequately sanitize or safely render4.6
- CVE-2025-31959HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images.3.5
- CVE-2025-31982HCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed directl3.7
- CVE-2025-31984HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header3.7
- CVE-2025-31983HCL BigFix Service Management (SM) is affected by a security misconfiguration vulnerability due to CSP header3.7
- CVE-2025-31957HCL BigFix Service Management (SM) is affected by a Cross‑Site Request Forgery (CSRF) vulnerability.2.6
- CVE-2025-31981HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption5.3
Product normalization is registry-driven with AI assist and human review. How it works