CVE-2024-42207: Hcltech Dryice Iautomate

Medium severity, CVSS 6.0. EPSS: 0.3% chance of exploitation in the next 30 days.

HCL iAutomate is affected by a session fixation vulnerability.  An attacker could hijack a victim's session ID from their authenticated session.

Affected products

  • Hcltech Dryice Iautomate: version 6.4.2 only

Published 2025-02-05. Last modified 2026-06-17.