CVE-2025-31952

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/07/2025
Last modified:
10/10/2025

Description

HCL iAutomate is affected by an insufficient session expiration. This allows tokens to remain valid indefinitely unless manually revoked, increasing the risk of unauthorized access.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hcltech:dryice_iautomate:6.5.1:*:*:*:*:*:*:*