Description
Agentflow BPM enterprise management system has improper authentication. A remote attacker with general user privilege can change the name of the user account to acquire arbitrary account privilege, and access, manipulate system or disrupt service.
No analysis available yet.
Remediation
Vendor Solution
Contact tech support from FLOWRING
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-41584 | Agentflow BPM enterprise management system has improper authentication. A remote attacker with general user privilege can change the name of the user account to acquire arbitrary account privilege, and access, manipulate system or disrupt service. |
References
History
Thu, 01 May 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2025-05-01T19:06:11.492Z
Reserved: 2022-08-30T00:00:00.000Z
Link: CVE-2022-39038
Updated: 2024-08-03T11:10:32.261Z
Status : Modified
Published: 2022-11-10T15:15:14.647
Modified: 2024-11-21T07:17:25.600
Link: CVE-2022-39038
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD