Vulnerability Description
In TARGIT Decision Suite 23.2.15007.0 before Autumn 2023, the session token is part of the URL and may be sent in a cleartext HTTP session.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://community.targit.com/hc/en-us/articles/12618082416028-Change-Log-On-prem
- https://community.targit.com/hc/en-us/articles/16112758176156-Vulnerabilities
- https://github.com/DMCERTCE/DecisionSuite_Token_in_Url
- https://community.targit.com/hc/en-us/articles/12618082416028-Change-Log-On-prem
- https://github.com/DMCERTCE/DecisionSuite_Token_in_Url
FAQ
What is CVE-2024-36426?
CVE-2024-36426 is a vulnerability with a CVSS score of 7.5 (HIGH). In TARGIT Decision Suite 23.2.15007.0 before Autumn 2023, the session token is part of the URL and may be sent in a cleartext HTTP session.
How severe is CVE-2024-36426?
CVE-2024-36426 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-36426?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.