Improper authentication and missing CSRF protection in the local setup interface component in HCL BigFix IVR version 4.2 allows a local attacker to perform unauthorized configuration changes via unauthenticated administrative configuration requests.
References
| Link | Resource |
|---|---|
| https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0127753 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-01-07 12:17
Updated : 2026-01-22 13:45
NVD link : CVE-2025-31963
Mitre link : CVE-2025-31963
CVE.ORG link : CVE-2025-31963
JSON object : View
Products Affected
hcltech
- bigfix_insights_for_vulnerability_remediation
