PT-2026-1582 · Hcl · Hcl Bigfix Ivr
Published
2026-01-07
·
Updated
2026-01-21
·
CVE-2025-31964
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
HCL BigFix IVR version 4.2
Description
A configuration issue with service binding in internal service components allows a privileged attacker to affect service availability. This occurs because administrative services are exposed through external network interfaces instead of the intended local authentication interface.
Recommendations
Ensure proper service binding configuration for internal service components in HCL BigFix IVR version 4.2.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hcl Bigfix Ivr