First published: Fri Sep 27 2024(Updated: )
HCL Nomad is susceptible to an insufficient session expiration vulnerability. Under certain circumstances, an unauthenticated attacker could obtain old session information.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
HCL Nomad | <1.0.13 | |
HCL Domino |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-23586 has been classified with a moderate severity level due to the potential for unauthorized access to session data.
To mitigate CVE-2024-23586, ensure that your HCL Nomad software is updated to version 1.0.13 or later, where this vulnerability is addressed.
CVE-2024-23586 affects users of HCL Nomad versions prior to 1.0.13 who may be vulnerable to session hijacking.
CVE-2024-23586 is an insufficient session expiration vulnerability allowing potential unauthorized access to session information.
Yes, CVE-2024-23586 can be exploited by unauthenticated attackers remotely under specific circumstances.