PT-2009-4680 · Midgard Information Management System · Midas

Hxh

·

Published

2009-06-26

·

Updated

2017-09-19

·

CVE-2009-2231

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MIDAS version 1.43
Description The issue allows remote attackers to bypass authentication and obtain administrative access via an admin account record in a MIDAS cookie.
Recommendations For MIDAS version 1.43, update to a version that fixes this issue, as the current version allows unauthorized access to administrative functions.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-2231

Affected Products

Midas