Junglewise Threat Intelligence

CVE-2025-31985: HCL BigFix Service Management missing X-Content-Type-Options header

CVE-2025-31985 · Severity: low · CVSS 3.7 · Published 2026-05-20

Vendors: HCL.

Executive brief

HCL BigFix Service Management, a tool used for IT service and asset management, contains a security misconfiguration in its web interface. This flaw could allow a user's web browser to incorrectly interpret file types, potentially leading to the execution of malicious scripts. While the risk is low and requires specific user interaction, it could lead to unauthorized access to limited information or minor service disruptions.

Technical details

HCL BigFix Service Management (SM) fails to properly implement the 'X-Content-Type-Options: nosniff' HTTP response header. This omission allows web browsers to perform MIME-type sniffing, where the browser ignores the declared Content-Type and attempts to determine the file type based on its content. An attacker could leverage this behavior to trick a browser into executing malicious code disguised as a non-executable file type (e.g., an image containing JavaScript). Exploitation requires a network-based attacker with low privileges and some level of user interaction. The vulnerability is tracked as CWE-200 and CWE-16, potentially leading to limited information disclosure or availability impacts.

Affected products

  • HCL BigFix Service Management (SM)

Timeline

  • 2026-05-20: advisory: Initial advisory published by HCL Software and NVD.

References