In the Bentley ALIM Web application, certain configuration settings can cause exposure of a user's ALIM session token when the user attempts to download files. This is fixed in Assetwise ALIM Web 23.00.04.04 and Assetwise Information Integrity Server 23.00.02.03.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.bentley.com/advisories/be-2024-0001/ |
|
History
Wed, 14 Aug 2024 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-488 CWE-613 |
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-14T14:47:22.686Z
Reserved: 2024-02-26T00:00:00
Link: CVE-2024-27455
Updated: 2024-08-02T00:34:52.225Z
Status : Awaiting Analysis
Published: 2024-02-26T16:28:00.707
Modified: 2024-11-21T09:04:38.400
Link: CVE-2024-27455
No data.
OpenCVE Enrichment
No data.