CVE-2025-31962: HCL BigFix IVR is impacted by an insufficient session expiration vulnerability
Insufficient session expiration in the Web UI authentication component in HCL BigFix IVR version 4.2 allows an authenticated attacker to gain prolonged unauthorized access to protected API endpoints due to excessive expiration periods.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31962?
CVE-2025-31962 has a medium severity rating due to the potential for unauthorized access to protected API endpoints.
How do I fix CVE-2025-31962?
To fix CVE-2025-31962, update to the latest version of HCL BigFix IVR that includes session expiration improvements.
Who is affected by CVE-2025-31962?
Users of HCL BigFix IVR version 4.2 are affected by CVE-2025-31962 due to insufficient session expiration.
What are the potential impacts of CVE-2025-31962?
The potential impacts of CVE-2025-31962 include prolonged unauthorized access to sensitive API endpoints.
Is there a workaround for CVE-2025-31962?
A temporary workaround for CVE-2025-31962 may include manually monitoring and terminating sessions that are held open for excessive periods.