// For flags

CVE-2023-37504

An insufficient session expiration vulnerability affects HCL Compass

Severity Score

6.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Attend
*SSVC
Descriptions

HCL Compass is vulnerable to failure to invalidate sessions. The application does not invalidate authenticated sessions when the log out functionality is called.  If the session identifier can be discovered, it could be replayed to the application and used to impersonate the user.

HCL Compass es vulnerable a no invalidar las sesiones. La aplicación no invalida las sesiones autenticadas cuando se llama a la función de cierre de sesión. Si se puede descubrir el identificador de sesión, podría reproducirse en la aplicación y usarse para hacerse pasar por el usuario.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
High
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:Attend
Exploitation
None
Automatable
Yes
Tech. Impact
Partial
* Organization's Worst-case Scenario
Timeline
  • 2023-07-06 CVE Reserved
  • 2023-10-19 CVE Published
  • 2024-09-12 CVE Updated
  • 2024-10-25 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-613: Insufficient Session Expiration
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Hcltech
Search vendor "Hcltech"
Hcl Compass
Search vendor "Hcltech" for product "Hcl Compass"
>= 2.0.0 <= 2.0.3
Search vendor "Hcltech" for product "Hcl Compass" and version " >= 2.0.0 <= 2.0.3"
-
Affected
Hcltech
Search vendor "Hcltech"
Hcl Compass
Search vendor "Hcltech" for product "Hcl Compass"
>= 2.2.0 < 2.2.3
Search vendor "Hcltech" for product "Hcl Compass" and version " >= 2.2.0 < 2.2.3"
-
Affected
Hcltech
Search vendor "Hcltech"
Hcl Compass
Search vendor "Hcltech" for product "Hcl Compass"
2.1.0
Search vendor "Hcltech" for product "Hcl Compass" and version "2.1.0"
-
Affected