PT-2012-3572 · Autoform · Autoform Pdm Archive
David Elze
·
Published
2012-06-13
·
Updated
2012-09-29
·
CVE-2012-1827
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
AutoFORM PDM Archive versions prior to 7.1
Description
The issue concerns a lack of authorization requirements in the web service of the affected software. This allows remote authenticated users to perform database operations via a SOAP request. For example, this can be achieved through the "initializeQueryDatabase2" request.
Recommendations
For versions prior to 7.1, consider restricting access to the web service to minimize the risk of unauthorized database operations until a patch is available. As a temporary workaround, limit the ability to perform database operations via SOAP requests to only necessary users.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Autoform Pdm Archive