Session Fixation
CVE-2024-42207
Summary
HCL iAutomate is affected by a session fixation vulnerability. An attacker could hijack a victim's session ID from their authenticated session.
- HIGH
- NETWORK
- LOW
- UNCHANGED
- NONE
- HIGH
- HIGH
- LOW
CWE-384 - Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
References
Advisory Timeline
- Published