CVE-2020-14247: Medium severity hcl tech onetest performance vulnerability
Published Feb 4, 2021
·Updated
HCL OneTest Performance V9.5, V10.0, V10.1 contains an inadequate session timeout, which could allow an attacker time to guess and use a valid session ID.
Affected Software
3 affected components
Hcltechsw Onetest Performance=9.5.0
Hcltechsw Onetest Performance=10.0.0
Hcltechsw Onetest Performance=10.1.0
Event History
Feb 4, 2021
CVE Published
via MITRE·06:43 AM
Data Sourced
via MITRE·06:43 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-14247.
2
What is the severity of CVE-2020-14247?
The severity of CVE-2020-14247 is medium.
3
Which version of HCL OneTest Performance is affected by CVE-2020-14247?
HCL OneTest Performance versions 9.5, 10.0, and 10.1 are affected by CVE-2020-14247.
4
What is the impact of CVE-2020-14247?
CVE-2020-14247 could allow an attacker time to guess and use a valid session ID.
5
Is there a fix available for CVE-2020-14247?
Yes, it is recommended to refer to the official HCL OneTest Performance support article for instructions on fixing CVE-2020-14247.