Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xcc4-j2gc-c9xj

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Veritas APTARE versions prior to 10.5 included code that bypassed the normal login process when specific authentication credentials were provided to the server. An unauthenticated user could login to the application and gain access to the data and functionality accessible to the targeted user account.

Veritas APTARE versions prior to 10.5 included code that bypassed the normal login process when specific authentication credentials were provided to the server. An unauthenticated user could login to the application and gain access to the data and functionality accessible to the targeted user account.

EPSS

Процентиль: 76%
0.00928
Низкий

Связанные уязвимости

CVSS3: 8.1
nvd
больше 5 лет назад

Veritas APTARE versions prior to 10.5 included code that bypassed the normal login process when specific authentication credentials were provided to the server. An unauthenticated user could login to the application and gain access to the data and functionality accessible to the targeted user account.

CVSS3: 8.1
fstec
больше 5 лет назад

Уязвимость платформы для управления данными APTARE, связанная с обходом процедуры аутентификации, позволяющая нарушителю получить доступ к данным и функциям, доступным для целевой учетной записи пользователя

EPSS

Процентиль: 76%
0.00928
Низкий