RSS   Vulnerabilities for 'Onetest performance'   RSS

2021-02-04
 
CVE-2020-14247

CWE-613
 

 
HCL OneTest Performance V9.5, V10.0, V10.1 contains an inadequate session timeout, which could allow an attacker time to guess and use a valid session ID.

 
 
CVE-2020-14246

CWE-522
 

 
HCL OneTest Performance V9.5, V10.0, V10.1 uses basic authentication which is relatively weak. An attacker could potentially decode the encoded credentials.

 
 
CVE-2020-14245

CWE-287
 

 
HCL OneTest UI V9.5, V10.0, and V10.1 does not perform authentication for functionality that either requires a provable user identity or consumes a significant amount of resources.

 

 >>> Vendor: Hcltechsw 8 Products
Self-service application
Hcl verse
Hcl inotes
Hcl client application access
Hcl commerce
Onetest performance
Connections
Hcl launch


Copyright 2024, cxsecurity.com

 

Back to Top