Impact
The vulnerability occurs because the application does not enforce access control lists on certain functions, allowing unauthorized users to execute restricted operations. This flaw permits accessing functionality not properly constrained by ACLs. The weakness is identified as an authorization bypass, classified by CWE-862.
Affected Systems
The affected product is the Liman MYS system from HAVELSAN Inc. Version strings prior to the release identified as Master.1107 are impacted. No other vendors or versions are listed.
Risk and Exploitability
With a CVSS score of 8.3, the severity is considered High. The EPSS score is less than 1%, indicating low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the potential attack vector is through application interfaces where authorization checks are omitted, which may be reachable by users with or without credentials.
OpenCVE Enrichment