VendorsHcltechswonetest_performanceall versions
Vulnerabilities

Hcltechsw OneTest Performance

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2020-14245
HCL OneTest UI V9.5, V10.0, and V10.1 does not perform authentication for functionality that either requires a provable user identity or consumes a significant amount of resources.
Published 2021-02-04 · Modified
9.8EPSS 0.012
CVE-2020-14246
HCL OneTest Performance V9.5, V10.0, V10.1 uses basic authentication which is relatively weak. An attacker could potentially decode the encoded credentials.
Published 2021-02-04 · Modified
7.5EPSS 0.007
CVE-2020-14247
HCL OneTest Performance V9.5, V10.0, V10.1 contains an inadequate session timeout, which could allow an attacker time to guess and use a valid session ID.
Published 2021-02-04 · Modified
6.5EPSS 0.007