PT-2022-24692 · Unknown · Agentflow Bpm

Alan Chung

+1

·

Published

2022-11-10

·

Updated

2022-11-15

·

CVE-2022-39038

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Agentflow BPM enterprise management system (affected versions not specified)
Description The issue is related to improper authentication in the Agentflow BPM enterprise management system. A remote attacker with general user privilege can exploit this by changing the name of the user account to acquire arbitrary account privilege. This allows the attacker to access, manipulate the system, or disrupt the service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2022-39038

Affected Products

Agentflow Bpm