CVE-2025-31962

Source
https://cve.org/CVERecord?id=CVE-2025-31962
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-31962.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-31962
Published
2026-01-07T12:17:01.720Z
Modified
2026-03-12T20:18:19.921432Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

Insufficient session expiration in the Web UI authentication component in HCL BigFix IVR version 4.2 allows an authenticated attacker to gain prolonged unauthorized access to protected API endpoints due to excessive expiration periods.

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "4.2"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-31962.json"