Description
An issue was discovered in eteams OA v4.0.34. Because the session is not strictly checked, the account names and passwords of all employees in the company can be obtained by an ordinary account. Specifically, the attacker sends a jsessionid value for URIs under app/profile/summary/.
Published: 2019-09-09
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2019-6970 An issue was discovered in eteams OA v4.0.34. Because the session is not strictly checked, the account names and passwords of all employees in the company can be obtained by an ordinary account. Specifically, the attacker sends a jsessionid value for URIs under app/profile/summary/.
History

No history.

Subscriptions

Weaver Eteams Oa
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T01:10:41.105Z

Reserved: 2019-09-08T00:00:00.000Z

Link: CVE-2019-16133

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-09-09T03:15:10.577

Modified: 2024-11-21T04:30:07.167

Link: CVE-2019-16133

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses