CVE-2023-37504
Summary
| CVE | CVE-2023-37504 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-10-19 01:15:00 UTC |
| Updated | 2023-10-25 10:15:00 UTC |
| Description | HCL Compass is vulnerable to failure to invalidate sessions. The application does not invalidate authenticated sessions when the log out functionality is called. If the session identifier can be discovered, it could be replayed to the application and used to impersonate the user. |
Risk And Classification
Problem Types: CWE-613
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Hcltech | Hcl Compass | All | All | All | All |
| Application | Hcltech | Hcl Compass | 2.1.0 | All | All | All |
| Application | Hcltech | Hcl Compass | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Bulletin: An insufficient session expiration vulnerability affects HCL Compass (CVE-2023-37504) - Customer Support | MISC | support.hcltechsw.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.