CVE-2020-10714: Netapp Oncommand Insight

High severity, CVSS 7.5. EPSS: 1.5% chance of exploitation in the next 30 days.

A flaw was found in WildFly Elytron version 1.11.3.Final and before. When using WildFly Elytron FORM authentication with a session ID in the URL, an attacker could perform a session fixation attack. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Affected products

  • Netapp Oncommand Insight: affected versions not specified
  • Red Hat Codeready Studio: version 12.0 only
  • Red Hat Descision Manager: version 7.0 only
  • Red Hat JBoss Fuse: version 7.0.0 only
  • Red Hat Process Automation: version 7.0 only
  • Red Hat Wildfly Elytron: before 1.11.3 (fixed in 1.11.3)

Published 2020-09-23. Last modified 2026-06-17.