CVE Vulnerabilities

CVE-2025-31954

Use of GET Request Method With Sensitive Query Strings

Published: Nov 05, 2025 | Modified: Nov 07, 2025
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

HCL iAutomate v6.5.1 and v6.5.2 is susceptible to a sensitive information disclosure. An HTTP GET method is used to process a request and includes sensitive information in the query string of that request. An attacker could potentially access information or resources they were not intended to see.

Weakness

The web application uses the HTTP GET method to process a request and includes sensitive information in the query string of that request.

Affected Software

Name Vendor Start Version End Version
Dryice_iautomate Hcltech 6.5.1 (including) 6.5.1 (including)
Dryice_iautomate Hcltech 6.5.2 (including) 6.5.2 (including)

Potential Mitigations

References