The vendor explicitly identifies these products as affected by this CVE.
- QMS Automotive
- Summary
- The QMS.Mobile module of the affected application does not invalidate the session token on logout. This could allow an attacker to perform session hijacking attacks.
- Remediation
- Update to V12.39 or later version. The patch is available upon request from customer support
