Impact
The vulnerability is a missing authorization flaw in HAVELSAN's Liman MYS application, allowing attackers to access protected functionality without the required permissions. This flaw is categorized as a lack of proper access control (CWE‑862) and can be exploited to read or manipulate data that should only be available to authorized users. The primary impact is unauthorized data access or potential privilege escalation within the system, as sensitive operations can be performed by users who do not have the correct ACL entries.
Affected Systems
The flaw affects Liman MYS deployments with versions from 2.2.3 up to, but not including, 2.3.1. Users running any of those releases are potentially exposed, while versions 2.3.1 and later contain the fix. The vendor product is identified as HAVELSAN Inc.'s Liman MYS, a management system for ...
Risk and Exploitability
The CVSS base score is 8.8, indicating a high severity. The EPSS score is not reported, so precise likelihood of exploitation cannot be quantified, but the absence of KEV status suggests no currently known public exploitation. The attack vector requires the attacker to reach the application layer, either through an authenticated session or by invoking exposed endpoints that lack proper ACL checks. Once a user has network or local access to the system, the missing authorization can be leveraged, making the vulnerability particularly dangerous if internal users are compromised.
OpenCVE Enrichment