HCL Nomad is susceptible to an insufficient session expiration vulnerability.   Under certain circumstances, an unauthenticated attacker could obtain old session information.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-21081 HCL Nomad is susceptible to an insufficient session expiration vulnerability.   Under certain circumstances, an unauthenticated attacker could obtain old session information.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00158}

epss

{'score': 0.00172}


Mon, 07 Oct 2024 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Hcltech domino
Hcltech hcl Nomad
CPEs cpe:2.3:a:hcltech:domino:-:*:*:*:*:*:*:*
cpe:2.3:a:hcltech:hcl_nomad:*:*:*:*:*:-:*:*
Vendors & Products Hcltech domino
Hcltech hcl Nomad

Fri, 04 Oct 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Hcltech
Hcltech nomad Server On Domino
CPEs cpe:2.3:a:hcltech:nomad_server_on_domino:*:*:*:*:*:*:*:*
Vendors & Products Hcltech
Hcltech nomad Server On Domino
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 27 Sep 2024 21:30:00 +0000

Type Values Removed Values Added
Description HCL Nomad is susceptible to an insufficient session expiration vulnerability.   Under certain circumstances, an unauthenticated attacker could obtain old session information.
Title An insufficient session timeout vulnerability affects HCL Nomad server on Domino
Weaknesses CWE-613
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2024-10-04T13:56:37.356Z

Reserved: 2024-01-18T07:30:10.662Z

Link: CVE-2024-23586

cve-icon Vulnrichment

Updated: 2024-10-04T13:56:32.267Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-27T22:15:12.930

Modified: 2024-10-07T15:30:56.227

Link: CVE-2024-23586

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.