In SapphireIMS 4097_1, a guest user can create a local administrator account on any system that has SapphireIMS installed, because of an Insecure Direct Object Reference (IDOR) in the local user creation function.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2021-08-11T20:09:18

Updated: 2024-08-05T20:27:04.464Z

Reserved: 2017-11-06T00:00:00

Link: CVE-2017-16630

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-08-11T21:15:07.733

Modified: 2021-08-16T17:23:49.300

Link: CVE-2017-16630

cve-icon Redhat

No data.