Description

HCL iAutomate v6.5.1 and v6.5.2 is susceptible to a sensitive information disclosure. An HTTP GET method is used to process a request and includes sensitive information in the query string of that request. An attacker could potentially access information or resources they were not intended to see.

INFO

Published Date :

2025-11-05T18:23:21.019Z

Last Modified :

2025-11-05T18:46:53.781Z

Source :

HCL
AFFECTED PRODUCTS

The following products are affected by CVE-2025-31954 vulnerability.

Vendors Products
Hcltech
  • Dryice Iautomate
  • Iautomate
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-31954.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact