Description
The FlowMaster BPM Plus system from NewType has a privilege escalation vulnerability. Remote attackers with regular privileges can elevate their privileges to administrator by tampering with a specific cookie.
Published: 2024-10-15
Score: 8.8 High
EPSS: 1.2% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update Service Pack to version v5.3.1 or later.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-50252 The FlowMaster BPM Plus system from NewType has a privilege escalation vulnerability. Remote attackers with regular privileges can elevate their privileges to administrator by tampering with a specific cookie.
History

Thu, 17 Oct 2024 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Newtype
Newtype flowmaster Bpm Plus
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:newtype:flowmaster_bpm_plus:*:*:*:*:*:*:*:*
Vendors & Products Newtype
Newtype flowmaster Bpm Plus

Tue, 15 Oct 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared New Type
New Type flowmaster Bpm Plus
CPEs cpe:2.3:a:new_type:flowmaster_bpm_plus:*:*:*:*:*:*:*:*
Vendors & Products New Type
New Type flowmaster Bpm Plus
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Oct 2024 03:45:00 +0000

Type Values Removed Values Added
Description The FlowMaster BPM Plus system from NewType has a privilege escalation vulnerability. Remote attackers with regular privileges can elevate their privileges to administrator by tampering with a specific cookie.
Title NewType FlowMaster BPM Plus - Privilege Escalation
Weaknesses CWE-565
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

New Type Flowmaster Bpm Plus
Newtype Flowmaster Bpm Plus
cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2024-10-15T15:27:17.681Z

Reserved: 2024-10-15T01:57:22.952Z

Link: CVE-2024-9970

cve-icon Vulnrichment

Updated: 2024-10-15T15:27:13.689Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-15T04:15:04.793

Modified: 2024-10-17T20:33:59.873

Link: CVE-2024-9970

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses