CVE-2024-42207

HCL iAutomate is affected by a session fixation vulnerability.  An attacker could hijack a victim's session ID from their authenticated session.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hcltech:dryice_iautomate:6.4.2:*:*:*:*:*:*:*

History

10 Oct 2025, 16:27

Type Values Removed Values Added
First Time Hcltech dryice Iautomate
Hcltech
CPE cpe:2.3:a:hcltech:dryice_iautomate:6.4.2:*:*:*:*:*:*:*
References () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0118946 - () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0118946 - Vendor Advisory
Summary
  • (es) HCL iAutomate se ve afectado por una vulnerabilidad de fijación de sesión. Un atacante podría secuestrar el ID de sesión de una víctima de su sesión autenticada.

05 Feb 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-05 16:15

Updated : 2025-10-10 16:27


NVD link : CVE-2024-42207

Mitre link : CVE-2024-42207

CVE.ORG link : CVE-2024-42207


JSON object : View

Products Affected

hcltech

  • dryice_iautomate
CWE
CWE-384

Session Fixation