---
id: CVE-2025-31962
title: >-
  Insufficient session expiration in the Web UI authentication component in HCL
  BigFix IVR version 4.2 allows an authenticated attacker to gain prolonged
  unauthorized access to protected API endpoints due to excessive expiration
  periods.
summary: >-
  Insufficient session expiration in the Web UI authentication component in HCL
  BigFix IVR version 4.2 allows an authenticated attacker to gain prolonged
  unauthorized access to protected API endpoints due to excessive expiration
  periods.
severity: low
cvss: 2
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N'
cwe:
  - CWE-613
vendor: hcltech
product: bigfix_insights_for_vulnerability_remediation
affected:
  - bigfix_insights_for_vulnerability_remediation = 4.2
published: '2026-01-07'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T22:10:00.273'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-31962'
references:
  - url: >-
      https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0127753
    label: psirt@hcl.com
tags:
  - nvd
epss: 0.00184
epssPercentile: 0.07206
ingestedAt: '2026-09-30T22:27:27.719Z'
---

## Overview

Insufficient session expiration in the Web UI authentication component in HCL BigFix IVR version 4.2 allows an authenticated attacker to gain prolonged unauthorized access to protected API endpoints due to excessive expiration periods.

## Affected

- `bigfix_insights_for_vulnerability_remediation = 4.2`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
