CVE 2 LOW

HCL BigFix IVR is impacted by an insufficient session expiration vulnerability_CVE-2025-31962

2 / 10
LOW
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N

Description

Insufficient session expiration in the Web UI authentication component in HCL BigFix IVR version 4.2 allows an authenticated attacker to gain prolonged unauthorized access to protected API endpoints due to excessive expiration periods.

Basic Information

ID CVE-2025-31962
Source HCL
Published Jan 7, 2026 at 06:48

Affected Product

Vendor HCLSoftware
Product BigFix IVR
Version 4.2
Affected Versions HCLSoftware BigFix IVR 4.2

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.