Insufficient Session Expiration in HCL BigFix IVR Compromises Security
CVE-2025-31962

2LOW

Key Information:

Vendor
CVE Published:
7 January 2026

What is CVE-2025-31962?

The HCL BigFix IVR version 4.2 contains a vulnerability in its Web UI authentication component, where insufficient session expiration settings can lead to prolonged unauthorized access to secure API endpoints. An authenticated attacker may exploit this weakness by maintaining an active session beyond its intended duration, potentially compromising sensitive information and system integrity.

Affected Version(s)

BigFix IVR 4.2

References

CVSS V3.1

Score:
2
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.