CVE-2024-42170
CVSS 3.1 Score 6.8 of 10 (medium)
Details
Summary
CVE-2024-42170 is a newly disclosed vulnerability that poses a threat to HCL MyXalytics. This issue permits session fixation, enabling cybercriminals to manipulate URLs with stolen session tokens and gain unauthorized access to users' login sessions. This vulnerability could potentially lead to sensitive data exposure or unauthorized system modifications. It is crucial for HCL to release a patch as soon as possible to mitigate this risk. Until then, users are advised to be cautious when clicking on unverified links and to implement multi-factor authentication to strengthen their security posture.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- DRYiCE MyXalytics