PT-2026-1582 · Hcl · Hcl Bigfix Ivr

Published

2026-01-07

·

Updated

2026-01-21

·

CVE-2025-31964

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions HCL BigFix IVR version 4.2
Description A configuration issue with service binding in internal service components allows a privileged attacker to affect service availability. This occurs because administrative services are exposed through external network interfaces instead of the intended local authentication interface.
Recommendations Ensure proper service binding configuration for internal service components in HCL BigFix IVR version 4.2.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-31964

Affected Products

Hcl Bigfix Ivr