HCL iAutomate v6.5.1 and v6.5.2 is susceptible to a sensitive information disclosure. An HTTP GET method is used to process a request and includes sensitive information in the query string of that request. An attacker could potentially access information or resources they were not intended to see.
Metrics
Affected Vendors & Products
References
History
Fri, 07 Nov 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hcltech dryice Iautomate
|
|
| CPEs | cpe:2.3:a:hcltech:dryice_iautomate:6.5.1:*:*:*:*:*:*:* cpe:2.3:a:hcltech:dryice_iautomate:6.5.2:*:*:*:*:*:*:* |
|
| Vendors & Products |
Hcltech dryice Iautomate
|
Thu, 06 Nov 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hcltech
Hcltech iautomate |
|
| Vendors & Products |
Hcltech
Hcltech iautomate |
Wed, 05 Nov 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 05 Nov 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HCL iAutomate v6.5.1 and v6.5.2 is susceptible to a sensitive information disclosure. An HTTP GET method is used to process a request and includes sensitive information in the query string of that request. An attacker could potentially access information or resources they were not intended to see. | |
| Title | HCL iAutomate is susceptible to a sensitive information disclosure | |
| Weaknesses | CWE-598 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HCL
Published: 2025-11-05T18:23:21.019Z
Updated: 2025-11-05T18:46:53.781Z
Reserved: 2025-04-01T18:46:19.517Z
Link: CVE-2025-31954
Updated: 2025-11-05T18:46:42.432Z
Status : Analyzed
Published: 2025-11-05T19:15:51.010
Modified: 2025-11-07T18:05:06.323
Link: CVE-2025-31954
No data.