PT-2024-21908 · Bentley · Assetwise Alim Web+1
Published
2024-02-25
·
Updated
2024-08-14
·
CVE-2024-27455
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Assetwise ALIM Web versions prior to 23.00.04.04
Assetwise Information Integrity Server versions prior to 23.00.02.03
Description
The issue arises in the Bentley ALIM Web application when certain configuration settings cause exposure of a user's ALIM session token during file downloads.
Recommendations
For Assetwise ALIM Web versions prior to 23.00.04.04, update to version 23.00.04.04 to resolve the issue.
For Assetwise Information Integrity Server versions prior to 23.00.02.03, update to version 23.00.02.03 to resolve the issue.
Fix
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Assetwise Alim Web
Assetwise Information Integrity Server