PT-2020-10198 · Halvotec · Raquest
Dominique Righetto
+1
·
Published
2020-03-13
·
Updated
2021-12-21
·
CVE-2019-19611
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Halvotec RaQuest versions prior to 10.24.11206.1
Description
An issue was discovered that allows an anonymous user to access the list of connected users as well as the session cookie for each user through one of the exposed web services.
Recommendations
For versions prior to 10.24.11206.1, update to Release 10.24.11206.1 to resolve the issue. As a temporary workaround, consider restricting access to the exposed web services until the update is applied.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Raquest