Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ch77-2q3c-8f9w

Опубликовано: 07 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 2

Описание

Insufficient session expiration in the Web UI authentication component in HCL BigFix IVR version 4.2 allows an authenticated attacker to gain prolonged unauthorized access to protected API endpoints due to excessive expiration periods.

Insufficient session expiration in the Web UI authentication component in HCL BigFix IVR version 4.2 allows an authenticated attacker to gain prolonged unauthorized access to protected API endpoints due to excessive expiration periods.

EPSS

Процентиль: 10%
0.00034
Низкий

2 Low

CVSS3

Дефекты

CWE-613

Связанные уязвимости

CVSS3: 2
nvd
около 1 месяца назад

Insufficient session expiration in the Web UI authentication component in HCL BigFix IVR version 4.2 allows an authenticated attacker to gain prolonged unauthorized access to protected API endpoints due to excessive expiration periods.

EPSS

Процентиль: 10%
0.00034
Низкий

2 Low

CVSS3

Дефекты

CWE-613