PT-2016-4860 · Dte Energy · Dte Energy Insight

Jeffrey Quesnelle

·

Published

2016-03-12

·

Updated

2016-03-19

·

CVE-2016-1562

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions DTE Energy Insight application versions prior to 1.7.8
Description The issue concerns the REST API in the DTE Energy Insight application, where remote authenticated users can obtain unspecified customer information. This is achieved by using a SQL expression in the filter parameter.
Recommendations For versions prior to 1.7.8, update to version 1.7.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the REST API or limiting the use of the filter parameter until the update is applied.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-1562

Affected Products

Dte Energy Insight