PT-2024-17502 · Shenzhen Dashi Tongzhou Information Technology · Agilebpm

Dsh1

·

Published

2024-12-05

·

Updated

2025-11-12

·

CVE-2024-12235

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Shenzhen Dashi Tongzhou Information Technology AgileBPM version 1.0.0
Description A critical issue has been found, affecting the doFilter function of the AuthorizationTokenCheckFilter.java file. This leads to improper access controls, allowing remote attacks. The issue has been publicly disclosed.
Recommendations For AgileBPM version 1.0.0, as a temporary workaround, consider disabling the doFilter function of the AuthorizationTokenCheckFilter.java file until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2024-12235

Affected Products

Agilebpm