Kiteworks MFT 7.5 may allow an unauthorized user to reset other users' passwords. This is fixed in version 7.6 and later.
References
Link | Resource |
---|---|
https://www.kiteworks.com/platform/simple/managed-file-transfer/ | Product |
https://github.com/accellion/CVEs/blob/main/CVE-2022-24110.txt | Third Party Advisory |
Configurations
Information
Published : 2022-02-14 04:15
Updated : 2022-02-22 13:36
NVD link : CVE-2022-24110
Mitre link : CVE-2022-24110
JSON object : View
CWE
CWE-863
Incorrect Authorization
Products Affected
accellion
- managed_file_transfer