PT-2016-4860 · Dte Energy · Dte Energy Insight

Jeffrey Quesnelle

·

Publicado

2016-03-12

·

Atualizado

2016-03-19

·

CVE-2016-1562

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions DTE Energy Insight application versions prior to 1.7.8
Description The issue concerns the REST API in the DTE Energy Insight application, where remote authenticated users can obtain unspecified customer information. This is achieved by using a SQL expression in the filter parameter.
Recommendations For versions prior to 1.7.8, update to version 1.7.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the REST API or limiting the use of the filter parameter until the update is applied.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-1562

Produtos afetados

Dte Energy Insight