ZeroHour

CVE-2025-31954

CVSS 3.1
4.3 medium
EPSS
<1%p8
Published
()
Modified
Description

HCL iAutomate v6.5.1 and v6.5.2 is susceptible to a sensitive information disclosure. An HTTP GET method is used to process a request and includes sensitive information in the query string of that request. An attacker could potentially access information or resources they were not intended to see.

Vendors
hcltech
Products
dryice iautomate
Weakness
CWE-598
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.