Session Fixation Vulnerability in HCL iAutomate
CVE-2024-42207
5.5MEDIUM
Key Information:
- Vendor
- HCL Software Software
- Status
- Iautomate
- Vendor
- CVE Published:
- 5 February 2025
Summary
HCL iAutomate is susceptible to a session fixation vulnerability, which allows attackers to hijack a victim's authenticated session by exploiting their session ID. By manipulating session IDs during the authentication process, an attacker can gain unauthorized access to sensitive information. This poses significant security risks for users as their ongoing sessions may be compromised without their knowledge.
Affected Version(s)
iAutomate 6.4.2
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved