PT-2014-3578 · Artiva+1 · Artiva Architect+4
Published
2014-04-15
·
Updated
2014-04-15
·
CVE-2014-0348
CVSS v2.0
3.5
Low
| Vector | AV:N/AC:M/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Artiva Workstation versions 1.3.x through 1.3.8
Artiva Rm version 3.1 MR7
Artiva Healthcare version 5.2 MR5
Artiva Architect version 3.2 MR5
Description
The issue allows remote attackers to login to arbitrary domain accounts by using the corresponding
username on a Windows client machine when the domain-name option is enabled in the Single Sign-On (SSO) implementation.Recommendations
For Artiva Workstation versions 1.3.x through 1.3.8, update to version 1.3.9 or later.
For Artiva Rm version 3.1 MR7, consider disabling the SSO implementation until a patch is available.
For Artiva Healthcare version 5.2 MR5, restrict access to the SSO feature to minimize the risk of exploitation.
For Artiva Architect version 3.2 MR5, avoid using the
domain-name option in the SSO configuration until the issue is resolved.Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Artiva Architect
Artiva Healthcare
Artiva Rm
Artiva Workstation
Windows