Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2wr7-99vr-6m4h

Опубликовано: 18 мар. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.4

Описание

Improper authorization in the report management and creation module of BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users to read and make unauthorized changes to any reports available within the application, even without proper permissions. The attacker must know the unique identifier of the report they want to manipulate.

Fix for 9.0.20 branch was released in version 9.0.20.238. Fix for 9.0.21 branch was released in version 9.0.21.201.

Improper authorization in the report management and creation module of BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users to read and make unauthorized changes to any reports available within the application, even without proper permissions. The attacker must know the unique identifier of the report they want to manipulate.

Fix for 9.0.20 branch was released in version 9.0.20.238. Fix for 9.0.21 branch was released in version 9.0.21.201.

EPSS

Процентиль: 21%
0.00068
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-639
CWE-863

Связанные уязвимости

CVSS3: 6.4
nvd
почти 2 года назад

Improper authorization in the report management and creation module of BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users to read and make unauthorized changes to any reports available within the application, even without proper permissions. The attacker must know the unique identifier of the report they want to manipulate. Fix for 9.0.20 branch was released in version 9.0.20.238. Fix for 9.0.21 branch was released in version 9.0.21.201.

EPSS

Процентиль: 21%
0.00068
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-639
CWE-863