CVE Vulnerabilities

CVE-2025-31987

Asymmetric Resource Consumption (Amplification)

Published: Aug 14, 2025 | Modified: Nov 21, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

HCL Connections Docs may mishandle validation of certain uploaded documents leading to denial of service due to resource exhaustion.

Weakness

The product does not properly control situations in which an adversary can cause the product to consume or produce excessive resources without requiring the adversary to invest equivalent work or otherwise prove authorization, i.e., the adversary’s influence is “asymmetric.”

Affected Software

NameVendorStart VersionEnd Version
Connections_docsHcltech2.0.2 (including)2.0.2 (including)

Potential Mitigations

References