First published: Thu Feb 04 2021(Updated: )
HCL OneTest Performance V9.5, V10.0, V10.1 contains an inadequate session timeout, which could allow an attacker time to guess and use a valid session ID.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hcltechsw Onetest Performance | =9.5.0 | |
Hcltechsw Onetest Performance | =10.0.0 | |
Hcltechsw Onetest Performance | =10.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-14247.
The severity of CVE-2020-14247 is medium.
HCL OneTest Performance versions 9.5, 10.0, and 10.1 are affected by CVE-2020-14247.
CVE-2020-14247 could allow an attacker time to guess and use a valid session ID.
Yes, it is recommended to refer to the official HCL OneTest Performance support article for instructions on fixing CVE-2020-14247.