CVE-2025-31985: HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header
HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header. This could allow browsers to perform MIME-type sniffing, potentially causing malicious content to be interpreted and executed incorrectly.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31985?
CVE-2025-31985 is classified as a high-severity vulnerability due to its potential to allow content type confusion attacks.
How do I fix CVE-2025-31985?
To fix CVE-2025-31985, ensure that the 'X-Content-Type-Options' HTTP header is properly configured and set to 'nosniff'.
What products are affected by CVE-2025-31985?
CVE-2025-31985 affects HCL BigFix Service Management.
What is the impact of CVE-2025-31985?
The impact of CVE-2025-31985 includes the risk of attackers executing malicious content type mismatches leading to unauthorized actions.
Is there a workaround for CVE-2025-31985?
A possible workaround for CVE-2025-31985 is to manually set security headers in the server configuration to mitigate the risk of exploitation.