Home

Description

A File Upload Validation Bypass vulnerability has been identified in the HCL BigFix SM, where the application fails to properly enforce file type restrictions during the upload process. An attacker may exploit this flaw to upload malicious or unauthorized files, such as scripts, executables, or web shells, by bypassing client-side or server-side validation mechanisms.

PUBLISHED Reserved 2025-04-01 | Published 2025-08-28 | Updated 2025-08-28 | Assigner HCL




MEDIUM: 5.4CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Problem types

CWE-434 Unrestricted Upload of File with Dangerous Type

Product status

Default status
unaffected

23
affected

References

support.hcl-software.com/...rticle&sysparm_article=KB0123631

cve.org (CVE-2025-31979)

nvd.nist.gov (CVE-2025-31979)

Download JSON