Description
Under certain circumstances an unauthenticated user could access the the web API for Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions prior to 11.0.2 and enumerate users.
Published: 2022-07-22
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update all Metasys ADS/ADX/OAS 10 versions with patch 10.1.6

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-22821 Under certain circumstances an unauthenticated user could access the the web API for Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions prior to 11.0.2 and enumerate users.
History

No history.

Subscriptions

Johnsoncontrols Metasys Application And Data Server Metasys Extended Application And Data Server Metasys Open Application Server
cve-icon MITRE

Status: PUBLISHED

Assigner: jci

Published:

Updated: 2024-09-16T17:07:41.371Z

Reserved: 2021-07-06T00:00:00.000Z

Link: CVE-2021-36200

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-07-22T15:15:07.910

Modified: 2024-11-21T06:13:18.243

Link: CVE-2021-36200

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses