A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.8), Teamcenter V13.0 (All versions < V13.0.0.7), Teamcenter V13.1 (All versions < V13.1.0.5), Teamcenter V13.2 (All versions < 13.2.0.2). The "surrogate" functionality on the user profile of the application does not perform sufficient access control that could lead to an account takeover. Any profile on the application can perform this attack and access any other user assigned tasks via the "inbox/surrogate tasks".
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: siemens
Published: 2021-09-14T10:47:58
Updated: 2024-08-04T02:44:09.181Z
Reserved: 2021-09-01T00:00:00
Link: CVE-2021-40354
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-09-14T11:15:26.667
Modified: 2024-11-21T06:23:56.200
Link: CVE-2021-40354
Redhat
No data.