PT-2025-2896 · Unknown · Becn Datagerry

0Xbytehunter

·

Published

2025-01-17

·

Updated

2025-01-17

·

CVE-2024-50967

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Becon DATAGerry versions prior to 2.3
Description The /rest/rights/ REST API endpoint contains an Incorrect Access Control issue, allowing an attacker to remotely access this endpoint without authentication. This leads to the unauthorized disclosure of sensitive information.
Recommendations For versions prior to 2.3, update to version 2.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the /rest/rights/ endpoint until a patch is available.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-50967

Affected Products

Becn Datagerry