The FlowMaster BPM Plus system from NewType has a privilege escalation vulnerability. Remote attackers with regular privileges can elevate their privileges to administrator by tampering with a specific cookie.
History

Thu, 17 Oct 2024 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Newtype
Newtype flowmaster Bpm Plus
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:newtype:flowmaster_bpm_plus:*:*:*:*:*:*:*:*
Vendors & Products Newtype
Newtype flowmaster Bpm Plus

Tue, 15 Oct 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared New Type
New Type flowmaster Bpm Plus
CPEs cpe:2.3:a:new_type:flowmaster_bpm_plus:*:*:*:*:*:*:*:*
Vendors & Products New Type
New Type flowmaster Bpm Plus
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Oct 2024 03:45:00 +0000

Type Values Removed Values Added
Description The FlowMaster BPM Plus system from NewType has a privilege escalation vulnerability. Remote attackers with regular privileges can elevate their privileges to administrator by tampering with a specific cookie.
Title NewType FlowMaster BPM Plus - Privilege Escalation
Weaknesses CWE-565
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2024-10-15T03:36:15.595Z

Updated: 2024-10-15T15:27:17.681Z

Reserved: 2024-10-15T01:57:22.952Z

Link: CVE-2024-9970

cve-icon Vulnrichment

Updated: 2024-10-15T15:27:13.689Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-15T04:15:04.793

Modified: 2024-10-17T20:33:59.873

Link: CVE-2024-9970

cve-icon Redhat

No data.