Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch and Apps Portal before 19.2.0.3 or 19.2.0.20240814, has incorrect authorization controls for the Admin functionality on the ThreatAvert Policy page. An authenticated user can navigate directly to the /#app/intelligence/threatAvertPolicies URI and disable policy enforcement.
Metrics
Affected Vendors & Products
References
History
Wed, 06 Nov 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-732 | |
Metrics |
cvssV3_1
|
ssvc
|
Wed, 06 Nov 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Akamai
Akamai secure Internet Access Enterprise Threatavert |
|
Weaknesses | CWE-863 | |
CPEs | cpe:2.3:a:akamai:secure_internet_access_enterprise_threatavert:19.2.0.2:*:*:*:*:*:*:* | |
Vendors & Products |
Akamai
Akamai secure Internet Access Enterprise Threatavert |
|
Metrics |
cvssV3_1
|
Mon, 04 Nov 2024 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch and Apps Portal before 19.2.0.3 or 19.2.0.20240814, has incorrect authorization controls for the Admin functionality on the ThreatAvert Policy page. An authenticated user can navigate directly to the /#app/intelligence/threatAvertPolicies URI and disable policy enforcement. | |
References |
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-11-04T00:00:00
Updated: 2024-11-06T16:18:38.490Z
Reserved: 2024-08-22T00:00:00
Link: CVE-2024-45164
Vulnrichment
Updated: 2024-11-06T16:18:32.432Z
NVD
Status : Modified
Published: 2024-11-04T14:15:14.677
Modified: 2024-11-06T17:35:33.437
Link: CVE-2024-45164
Redhat
No data.