Advanced Productivity Software DTE Axiom before 12.3.3 does not validate the registration ID, which allows remote attackers to bypass authentication and read or modify data about users, customers, and projects via unspecified vectors.
References
Link | Resource |
---|---|
http://www.osvdb.org/85499 | |
http://secunia.com/advisories/50508 | Vendor Advisory |
http://seclists.org/fulldisclosure/2012/Sep/62 |
Configurations
Information
Published : 2012-11-09 16:55
Updated : 2012-11-11 21:00
NVD link : CVE-2012-2455
Mitre link : CVE-2012-2455
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
advance_productivity_software
- dte_axiom