2026-05-06 13:50CVE-2025-52613HCL
PUBLISHED5.2CWE-200

HCL BigFix Service Management (SM) is affected by use of a vulnerable component

HCL BigFix Service Management (SM) is affected by use of a vulnerable WSGI Server was identified. Deploying an outdated or insecure WSGI server may expose the application to known security weaknesses, potentially increasing the risk of exploitation and unauthorized access.

Problem type

Affected products

HCL

BigFix Service Management (SM)

23 - AFFECTED

References

GitHub Security Advisories

GHSA-vrr6-hxxc-pgc8

HCL BigFix Service Management (SM) is affected by use of a vulnerable WSGI Server was identified....

https://github.com/advisories/GHSA-vrr6-hxxc-pgc8

HCL BigFix Service Management (SM) is affected by use of a vulnerable WSGI Server was identified. Deploying an outdated or insecure WSGI server may expose the application to known security weaknesses, potentially increasing the risk of exploitation and unauthorized access.

JSON source

https://cveawg.mitre.org/api/cve/CVE-2025-52613
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2025-52613",
    "assignerOrgId": "1e47fe04-f25f-42fa-b674-36de2c5e3cfc",
    "assignerShortName": "HCL",
    "dateUpdated": "2026-05-06T14:46:49.273Z",
    "dateReserved": "2025-06-18T14:00:40.357Z",
    "datePublished": "2026-05-06T13:50:47.494Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "1e47fe04-f25f-42fa-b674-36de2c5e3cfc",
        "shortName": "HCL",
        "dateUpdated": "2026-05-06T13:50:47.494Z"
      },
      "datePublic": "2026-05-06T16:15:00.000Z",
      "title": "HCL BigFix Service Management (SM) is affected by use of a vulnerable component",
      "descriptions": [
        {
          "lang": "en",
          "value": "HCL BigFix Service Management (SM) is affected by use of a vulnerable WSGI Server was identified. Deploying an outdated or insecure WSGI server may expose the application to known security weaknesses, potentially increasing the risk of exploitation and unauthorized access.",
          "supportingMedia": [
            {
              "type": "text/html",
              "base64": false,
              "value": "HCL BigFix Service Management (SM) is affected by use of a vulnerable WSGI Server was identified. Deploying an outdated or insecure WSGI server may expose the application to known security weaknesses, potentially increasing the risk of exploitation and unauthorized access."
            }
          ]
        }
      ],
      "affected": [
        {
          "vendor": "HCL",
          "product": "BigFix Service Management (SM)",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "23",
              "status": "affected"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "CWE-200: Exposure of Sensitive Information to an Unauthorized Actor",
              "cweId": "CWE-200",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0128144"
        }
      ],
      "metrics": [
        {
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ],
          "cvssV3_1": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L",
            "attackVector": "ADJACENT_NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "availabilityImpact": "LOW",
            "baseScore": 4.6,
            "baseSeverity": "MEDIUM"
          }
        }
      ]
    },
    "adp": [
      {
        "providerMetadata": {
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP",
          "dateUpdated": "2026-05-06T14:46:49.273Z"
        },
        "title": "CISA ADP Vulnrichment",
        "metrics": [
          {}
        ]
      }
    ]
  }
}