PT-2015-2437 · Accelerite · Accelerite Radia Client Automation
Published
2015-10-19
·
Updated
2016-12-24
·
CVE-2015-7862
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Accelerite Radia Client Automation (formerly HP Client Automation) versions 7.9 through 9.1
Description
The issue is related to the improper implementation of the Role Based Access Control feature, which might allow remote attackers to modify an account's role assignments. The vulnerability is associated with insufficient access control to certain functions, potentially enabling a remote attacker to change role assignments of an account.
Recommendations
For Accelerite Radia Client Automation versions 7.9 through 9.1, update to a version released after 2015-02-19 to resolve the issue. As a temporary workaround, consider restricting access to the Role Based Access Control feature until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Accelerite Radia Client Automation