PT-2015-2437 · Accelerite · Accelerite Radia Client Automation
Publicado
2015-10-19
·
Atualizado
2016-12-24
·
CVE-2015-7862
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Accelerite Radia Client Automation (formerly HP Client Automation) versions 7.9 through 9.1
Description
The issue is related to the improper implementation of the Role Based Access Control feature, which might allow remote attackers to modify an account's role assignments. The vulnerability is associated with insufficient access control to certain functions, potentially enabling a remote attacker to change role assignments of an account.
Recommendations
For Accelerite Radia Client Automation versions 7.9 through 9.1, update to a version released after 2015-02-19 to resolve the issue. As a temporary workaround, consider restricting access to the Role Based Access Control feature until a patch is available.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Accelerite Radia Client Automation