PT-2021-8564 · Unknown · Sapphireims
Tanoy Bose
·
Published
2021-08-11
·
Updated
2021-08-16
·
CVE-2017-16630
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SapphireIMS version 4097 1
Description
The issue allows a guest user to create a local administrator account on any system with SapphireIMS installed due to an Insecure Direct Object Reference (IDOR) in the local user creation function. This means that the function does not properly restrict access to objects, allowing unauthorized users to perform actions they should not be able to.
Recommendations
For SapphireIMS version 4097 1, consider restricting access to the local user creation function to prevent guest users from creating local administrator accounts until a patch is available. As a temporary workaround, limit the privileges of guest users to minimize the risk of exploitation.
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sapphireims