HCL iAutomate v6.5.1 and v6.5.2 is susceptible to a sensitive information disclosure. An HTTP GET method is used to process a request and includes sensitive information in the query string of that request. An attacker could potentially access information or resources they were not intended to see.
References
Configurations
No configuration.
History
05 Nov 2025, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-05 19:15
Updated : 2025-11-05 19:15
NVD link : CVE-2025-31954
Mitre link : CVE-2025-31954
CVE.ORG link : CVE-2025-31954
JSON object : View
Products Affected
No product.
CWE
CWE-598
Use of GET Request Method With Sensitive Query Strings
