PT-2002-1692 · Zmerge · Zmerge
Published
2002-09-10
·
Updated
2016-10-18
·
CVE-2002-0664
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
ZMerge versions 4.x through 5.x
Description
The default Access Control Lists (ACLs) of the administration database provides arbitrary users, including anonymous users, with Manager level access. This access allows users to read or modify import/export scripts.
Recommendations
For ZMerge versions 4.x through 5.x, update the default Access Control Lists (ACLs) to restrict Manager level access to authorized users only.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zmerge