HCL BigFix IVR
cpe:2.3:h:hcltech:legacy_ivr:*:*:*:*:*:*:*, +1 more
- 4.2
A vulnerability exists in the Web UI authentication component of HCL BigFix IVR version 4.2, where insufficient session expiration allows an authenticated attacker to maintain unauthorized access to protected API endpoints. This issue arises from excessively long expiration periods for sessions.
Exploitation of this vulnerability could lead to unauthorized access to protected API endpoints, allowing attackers to interact with these endpoints as if they were authorized users.
Users are advised to upgrade to HCL BigFix IVR version 4.2.1.0 or later. Instructions for upgrading are available in the BigFix Console under the 'Fixlets and Tasks' node.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.