Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-24qp-pvw9-442x

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics relies on client-side input validation, which allows remote authenticated users to bypass intended dual-control restrictions and modify data via crafted serialized objects, as demonstrated by limit manipulations.

RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics relies on client-side input validation, which allows remote authenticated users to bypass intended dual-control restrictions and modify data via crafted serialized objects, as demonstrated by limit manipulations.

EPSS

Процентиль: 93%
0.1001
Средний

Дефекты

CWE-20

Связанные уязвимости

nvd
около 11 лет назад

RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics relies on client-side input validation, which allows remote authenticated users to bypass intended dual-control restrictions and modify data via crafted serialized objects, as demonstrated by limit manipulations.

EPSS

Процентиль: 93%
0.1001
Средний

Дефекты

CWE-20