PT-2026-1575 · Hcl · Hcl Bigfix Ivr
Published
2026-01-07
·
Updated
2026-01-07
·
CVE-2025-31962
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
HCL BigFix IVR version 4.2
Description
The Web UI authentication component suffers from insufficient session expiration. This allows an authenticated attacker to maintain unauthorized access to protected API endpoints for an extended duration due to overly long expiration periods.
Recommendations
Update to a newer version that addresses the session expiration issue.
Fix
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hcl Bigfix Ivr