Insufficient Session Expiration in HCL BigFix IVR Compromises Security
CVE-2025-31962
2LOW
What is CVE-2025-31962?
The HCL BigFix IVR version 4.2 contains a vulnerability in its Web UI authentication component, where insufficient session expiration settings can lead to prolonged unauthorized access to secure API endpoints. An authenticated attacker may exploit this weakness by maintaining an active session beyond its intended duration, potentially compromising sensitive information and system integrity.
Affected Version(s)
BigFix IVR 4.2
