PT-2022-27076 · Unknown · Simmeth Lieferantenmanager

Steffen Robertz

·

Published

2022-12-25

·

Updated

2023-08-08

·

CVE-2022-44013

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Simmeth Lieferantenmanager versions prior to 5.6
Description An issue was discovered where an attacker can make various API calls without authentication because the password in a Credential Object is not checked. This allows unauthorized access to the system.
Recommendations For versions prior to 5.6, update to version 5.6 or later to resolve the issue. As a temporary workaround, consider restricting access to API endpoints to minimize the risk of exploitation. Avoid using the Credential Object without proper authentication until the issue is resolved.

Exploit

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2022-44013

Affected Products

Simmeth Lieferantenmanager