PT-2010-2899 · Sahana · Sap Hana

Published

2010-03-31

·

Updated

2018-10-10

·

CVE-2010-1191

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions Sahana disaster management system version 0.6.2.2
Description The issue allows remote attackers to bypass intended access restrictions and disable administrator authentication. This can be achieved via a direct request to "stream.php" in an "acl enable acl" action to the admin module.
Recommendations For version 0.6.2.2, consider restricting access to the "stream.php" file in the admin module to prevent unauthorized requests, and review the authentication mechanism to ensure it cannot be disabled by unauthorized users. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-1191

Affected Products

Sap Hana