SmartBPM.NET has a vulnerability of using hard-coded authentication key. An unauthenticated remote attacker can exploit this vulnerability to access system with regular user privilege to read application data, and execute submission and approval processes.
History

Tue, 12 Nov 2024 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2023-07-10T00:00:00

Updated: 2024-11-12T19:27:53.525Z

Reserved: 2023-06-30T00:00:00

Link: CVE-2023-37287

cve-icon Vulnrichment

Updated: 2024-08-02T17:09:33.993Z

cve-icon NVD

Status : Modified

Published: 2023-07-10T02:15:45.543

Modified: 2024-11-21T08:11:24.167

Link: CVE-2023-37287

cve-icon Redhat

No data.