CVE-2025-31962: Hcltech Bigfix Insights For Vulnerability Remediation
Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.
Insufficient session expiration in the Web UI authentication component in HCL BigFix IVR version 4.2 allows an authenticated attacker to gain prolonged unauthorized access to protected API endpoints due to excessive expiration periods.
Affected products
- Hcltech Bigfix Insights For Vulnerability Remediation: version 4.2 only
Published 2026-01-07. Last modified 2026-10-07.