PT-2012-3572 · Autoform · Autoform Pdm Archive

David Elze

·

Published

2012-06-13

·

Updated

2012-09-29

·

CVE-2012-1827

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions AutoFORM PDM Archive versions prior to 7.1
Description The issue concerns a lack of authorization requirements in the web service of the affected software. This allows remote authenticated users to perform database operations via a SOAP request. For example, this can be achieved through the "initializeQueryDatabase2" request.
Recommendations For versions prior to 7.1, consider restricting access to the web service to minimize the risk of unauthorized database operations until a patch is available. As a temporary workaround, limit the ability to perform database operations via SOAP requests to only necessary users.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-1827

Affected Products

Autoform Pdm Archive