Under certain circumstances an unauthenticated user could access the the web API for Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions prior to 11.0.2 and enumerate users.

Project Subscriptions

Vendors Products
Johnsoncontrols Subscribe
Metasys Application And Data Server Subscribe
Metasys Extended Application And Data Server Subscribe
Metasys Open Application Server Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2021-22821 Under certain circumstances an unauthenticated user could access the the web API for Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions prior to 11.0.2 and enumerate users.
Fixes

Solution

Update all Metasys ADS/ADX/OAS 10 versions with patch 10.1.6


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: jci

Published:

Updated: 2024-09-16T17:07:41.371Z

Reserved: 2021-07-06T00:00:00

Link: CVE-2021-36200

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-07-22T15:15:07.910

Modified: 2024-11-21T06:13:18.243

Link: CVE-2021-36200

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses