Session Fixation Vulnerability in HCL iAutomate
CVE-2024-42207

5.5MEDIUM

Key Information:

Vendor
HCL Software Software
Status
Iautomate
Vendor
CVE Published:
5 February 2025

Summary

HCL iAutomate is susceptible to a session fixation vulnerability, which allows attackers to hijack a victim's authenticated session by exploiting their session ID. By manipulating session IDs during the authentication process, an attacker can gain unauthorized access to sensitive information. This poses significant security risks for users as their ongoing sessions may be compromised without their knowledge.

Affected Version(s)

iAutomate 6.4.2

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.