Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch and Apps Portal before 19.2.0.3 or 19.2.0.20240814, has incorrect authorization controls for the Admin functionality on the ThreatAvert Policy page. An authenticated user can navigate directly to the /#app/intelligence/threatAvertPolicies URI and disable policy enforcement.
History

Wed, 06 Nov 2024 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-732
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Wed, 06 Nov 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Akamai
Akamai secure Internet Access Enterprise Threatavert
Weaknesses CWE-863
CPEs cpe:2.3:a:akamai:secure_internet_access_enterprise_threatavert:19.2.0.2:*:*:*:*:*:*:*
Vendors & Products Akamai
Akamai secure Internet Access Enterprise Threatavert
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}


Mon, 04 Nov 2024 13:45:00 +0000

Type Values Removed Values Added
Description Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch and Apps Portal before 19.2.0.3 or 19.2.0.20240814, has incorrect authorization controls for the Admin functionality on the ThreatAvert Policy page. An authenticated user can navigate directly to the /#app/intelligence/threatAvertPolicies URI and disable policy enforcement.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-11-04T00:00:00

Updated: 2024-11-06T16:18:38.490Z

Reserved: 2024-08-22T00:00:00

Link: CVE-2024-45164

cve-icon Vulnrichment

Updated: 2024-11-06T16:18:32.432Z

cve-icon NVD

Status : Modified

Published: 2024-11-04T14:15:14.677

Modified: 2024-11-06T17:35:33.437

Link: CVE-2024-45164

cve-icon Redhat

No data.