2
/ 10
LOW
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N
Description
Insufficient session expiration in the Web UI authentication component in HCL BigFix IVR version 4.2 allows an authenticated attacker to gain prolonged unauthorized access to protected API endpoints due to excessive expiration periods.
Basic Information
ID
CVE-2025-31962
Source
HCL
Published
Jan 7, 2026 at 06:48
Affected Product
Vendor
HCLSoftware
Product
BigFix IVR
Version
4.2
Affected Versions
HCLSoftware BigFix IVR 4.2