MoveSortedContentAction in C1 Financial Services Contelligent 9.1.4 does not check "the additional environment security configuration," which allows remote attackers with write permissions to reorder components.
References
Configurations
Information
Published : 2007-03-03 12:19
Updated : 2017-07-28 18:30
NVD link : CVE-2007-1249
Mitre link : CVE-2007-1249
JSON object : View
CWE
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Products Affected
contelligent
- c1_financial_services