PT-2020-10198 · Halvotec · Raquest

Dominique Righetto

+1

·

Published

2020-03-13

·

Updated

2021-12-21

·

CVE-2019-19611

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Halvotec RaQuest versions prior to 10.24.11206.1
Description An issue was discovered that allows an anonymous user to access the list of connected users as well as the session cookie for each user through one of the exposed web services.
Recommendations For versions prior to 10.24.11206.1, update to Release 10.24.11206.1 to resolve the issue. As a temporary workaround, consider restricting access to the exposed web services until the update is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2019-19611

Affected Products

Raquest