PT-2024-21908 · Bentley · Assetwise Alim Web+1

Published

2024-02-25

·

Updated

2024-08-14

·

CVE-2024-27455

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Assetwise ALIM Web versions prior to 23.00.04.04 Assetwise Information Integrity Server versions prior to 23.00.02.03
Description The issue arises in the Bentley ALIM Web application when certain configuration settings cause exposure of a user's ALIM session token during file downloads.
Recommendations For Assetwise ALIM Web versions prior to 23.00.04.04, update to version 23.00.04.04 to resolve the issue. For Assetwise Information Integrity Server versions prior to 23.00.02.03, update to version 23.00.02.03 to resolve the issue.

Fix

Insufficient Session Expiration

Weakness Enumeration

Related Identifiers

CVE-2024-27455

Affected Products

Assetwise Alim Web
Assetwise Information Integrity Server