Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Marek Klon

Researcher fromAccenture
#19574of 53,635
13.4Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2021-9607
5.3
2021-04-06
Openiam · Openam · CVE-2020-13419
**Name of the Vulnerable Software and Affected Versions** OpenIAM versions prior to 4.2.0.3 **Description** The issue allows Directory Traversal in the Batch task. **Recommendations** For versions prior to 4.2.0.3, update to version 4.2.0.3 or later to resolve the issue.
PT-2021-9610
8.1
2021-04-06
Openiam · Openam · CVE-2020-13422
**Name of the Vulnerable Software and Affected Versions** OpenIAM versions prior to 4.2.0.3 **Description** The issue concerns a lack of permission verification for users attempting to perform administrative actions through the "/webconsole/rest/api/*" endpoint. This means that users without proper permissions may be able to execute actions they should not have access to. **Recommendations** For versions prior to 4.2.0.3, update to version 4.2.0.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the "/webconsole/rest/api/*" endpoint to minimize the risk of exploitation.