Improper authentication and missing CSRF protection in the local setup interface component in HCL BigFix IVR version 4.2 allows a local attacker to perform unauthorized configuration changes via unauthenticated administrative configuration requests.
References
| Link | Resource |
|---|---|
| https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0127753 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
22 Jan 2026, 13:45
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0127753 - Vendor Advisory | |
| CPE | cpe:2.3:a:hcltech:bigfix_insights_for_vulnerability_remediation:4.2:*:*:*:*:*:*:* | |
| First Time |
Hcltech
Hcltech bigfix Insights For Vulnerability Remediation |
07 Jan 2026, 12:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-07 12:17
Updated : 2026-01-22 13:45
NVD link : CVE-2025-31963
Mitre link : CVE-2025-31963
CVE.ORG link : CVE-2025-31963
JSON object : View
Products Affected
hcltech
- bigfix_insights_for_vulnerability_remediation
