CVE-2025-31962 - HCL BigFix Session Expiration Vulnerability
CVE ID : CVE-2025-31962
Published : Jan. 7, 2026, 8:21 a.m. | 2 hours, 36 minutes ago
Description : Insufficient session expiration in the Web UI authentication component in HCL BigFix IVR version 4.2 allows an authenticated attacker to gain prolonged unauthorized access to protected API endpoints due to excessive expiration periods.
Severity: 2.0 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Jan. 7, 2026, 8:21 a.m. | 2 hours, 36 minutes ago
Description : Insufficient session expiration in the Web UI authentication component in HCL BigFix IVR version 4.2 allows an authenticated attacker to gain prolonged unauthorized access to protected API endpoints due to excessive expiration periods.
Severity: 2.0 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...