This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Logonbox First view 2019-03-21
Product Nervepoint Access Manager Last view 2019-03-21
Version 1.2 Type Application
Update rg3  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:logonbox:nervepoint_access_manager

Activity : Overall

Related : CVE

  Date Alert Description
9.4 2019-03-21 CVE-2019-6716

An unauthenticated Insecure Direct Object Reference (IDOR) in Wicket Core in LogonBox Nervepoint Access Manager 2013 through 2017 allows a remote attacker to enumerate internal Active Directory usernames and group names, and alter back-end server jobs (backup and synchronization jobs), which could allow for the possibility of a Denial of Service attack via a modified jobId parameter in a runJob.html GET request.

CWE : Common Weakness Enumeration

%idName
100% (1) CWE-639 Access Control Bypass Through User-Controlled Key