SICK Package Analytics software up to and including version V04.0.0 are vulnerable due to incorrect default permissions settings. An unauthorized attacker could read sensitive data from the system by querying for known files using the REST API directly.
References
Configurations
Information
Published : 2020-07-29 07:15
Updated : 2020-08-03 10:28
NVD link : CVE-2020-2077
Mitre link : CVE-2020-2077
JSON object : View
CWE
CWE-276
Incorrect Default Permissions
Products Affected
sick
- package_analytics