CVE-2024-42170

CVSS 3.1 Score 6.8 of 10 (medium)

Details

Published Jan 11, 2025
CWE ID 384

Summary

CVE-2024-42170 is a newly disclosed vulnerability that poses a threat to HCL MyXalytics. This issue permits session fixation, enabling cybercriminals to manipulate URLs with stolen session tokens and gain unauthorized access to users' login sessions. This vulnerability could potentially lead to sensitive data exposure or unauthorized system modifications. It is crucial for HCL to release a patch as soon as possible to mitigate this risk. Until then, users are advised to be cautious when clicking on unverified links and to implement multi-factor authentication to strengthen their security posture.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share