In TARGIT Decision Suite 23.2.15007.0 before Autumn 2023, the session token is part of the URL and may be sent in a cleartext HTTP session.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.