CVE-2024-41985: High severity SmartClient Opcenter QL Home vulnerability
A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >= V13.2 < V2506), SOA Cockpit (All versions >= V13.2 < V2506). The affected application does not expire the session without logout. This could allow an attacker to get unauthorized access if the session is left idle.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41985?
CVE-2024-41985 has a high severity as it allows session fixation vulnerabilities in SmartClient modules.
How do I fix CVE-2024-41985?
To fix CVE-2024-41985, ensure that session expiration is enforced for the affected SmartClient modules.
Which versions are affected by CVE-2024-41985?
CVE-2024-41985 affects SmartClient modules Opcenter QL Home, SOA Audit, and SOA Cockpit in versions from 13.2 to below 2506.
What impact does CVE-2024-41985 have on users?
The impact of CVE-2024-41985 is that an attacker could exploit the session staying active, potentially leading to unauthorized access.
Is there a need to immediately upgrade software to mitigate CVE-2024-41985?
Yes, it is recommended to upgrade the affected SmartClient software to mitigate the risks posed by CVE-2024-41985.