An insufficient session expiration vulnerability affects HCL Compass
CVE-2023-37504
7.1HIGH
What is CVE-2023-37504?
HCL Compass features a significant vulnerability associated with session management, where authenticated sessions remain active even after the logout function is executed. This flaw allows an attacker to exploit session identifiers, facilitating replay attacks that enable user impersonation within the application. It is crucial for organizations using HCL Compass to address this vulnerability promptly to enhance their security posture.
Affected Version(s)
HCL Compass 2.0, 2.1, 2.2