SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-37504

HCL Compass is vulnerable to failure to invalidate sessions.

MEDIUM 6.5EPSS 0.29%

Does this matter?

Lower severity and a low EPSS score (0.29%). Track it; it rarely justifies an emergency change on its own.

Description

HCL Compass is vulnerable to failure to invalidate sessions. The application does not invalidate authenticated sessions when the log out functionality is called.  If the session identifier can be discovered, it could be replayed to the application and used to impersonate the user.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS
0.29% probability · 22th percentile
CISA KEV
Not listed
Weakness
CWE-613
Affected
hcltech/hcl compass
Source
psirt@hcl.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.