7.1
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
Description
HCL iAutomate is affected by an insufficient session expiration. This allows tokens to remain valid indefinitely unless manually revoked, increasing the risk of unauthorized access.
Basic Information
ID
CVE-2025-31952
Source
HCL
Published
Jul 24, 2025 at 21:01
Modified
Jul 25, 2025 at 13:34
Affected Product
Vendor
HCL Software
Product
iAutomate
Version
6.5.1
Affected Versions
HCL Software iAutomate 6.5.1