Summary
Detail | |||
---|---|---|---|
Vendor | Logonbox | First view | 2019-03-21 |
Product | Nervepoint Access Manager | Last view | 2019-03-21 |
Version | 1.2 | Type | Application |
Update | rg3 | ||
Edition | * | ||
Language | * | ||
Sofware Edition | * | ||
Target Software | * | ||
Target Hardware | * | ||
Other | * | ||
CPE Product | cpe:2.3:a:logonbox:nervepoint_access_manager |
Activity : Overall
Related : CVE
Date | Alert | Description | |
---|---|---|---|
9.4 | 2019-03-21 | CVE-2019-6716 | An unauthenticated Insecure Direct Object Reference (IDOR) in Wicket Core in LogonBox Nervepoint Access Manager 2013 through 2017 allows a remote attacker to enumerate internal Active Directory usernames and group names, and alter back-end server jobs (backup and synchronization jobs), which could allow for the possibility of a Denial of Service attack via a modified jobId parameter in a runJob.html GET request. |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
100% (1) | CWE-639 | Access Control Bypass Through User-Controlled Key |