Advanced Productivity Software DTE Axiom before 12.3.3 does not validate the registration ID, which allows remote attackers to bypass authentication and read or modify data about users, customers, and projects via unspecified vectors.
References
Link | Resource |
---|---|
http://seclists.org/fulldisclosure/2012/Sep/62 | |
http://secunia.com/advisories/50508 | Vendor Advisory |
http://www.osvdb.org/85499 |
Configurations
History
No history.
Information
Published : 2012-11-10 00:55
Updated : 2012-11-12 05:00
NVD link : CVE-2012-2455
Mitre link : CVE-2012-2455
CVE.ORG link : CVE-2012-2455
JSON object : View
Products Affected
advance_productivity_software
- dte_axiom
CWE
CWE-264
Permissions, Privileges, and Access Controls