PT-2023-13435 · A4N · A4N
Alexandre Guldner
+1
·
Published
2023-02-27
·
Updated
2025-03-10
·
CVE-2022-34908
CVSS v3.1
8.2
High
| Vector | AC:L/AV:N/A:N/C:H/I:L/PR:N/S:U/UI:N |
Name of the Vulnerable Software and Affected Versions
A4N (Aremis 4 Nomad) application version 1.5.0
Description
An issue was discovered in the A4N application, which possesses an authentication mechanism. However, some features do not require any token or cookie in a request, allowing an attacker to send a simple HTTP request to the right endpoint and obtain authorization to retrieve application data.
Recommendations
For version 1.5.0, consider restricting access to sensitive endpoints until a patch is available, and ensure that all features require proper authentication tokens or cookies in requests. As a temporary workaround, disable any features that do not require authentication to minimize the risk of exploitation.
Fix
Missing Authentication
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
A4N