Impact
This vulnerability is an Insecure Direct Object Reference (IDOR) that allows an attacker who can control a key to bypass authorization checks in HAVELSAN Inc.'s Geographic Tracking System. The flaw permits the attacker to retrieve or manipulate data belonging to other users by modifying a trusted identifier, leading to potential data leakage and unauthorized changes. The weakness is categorized as CWE-639.
Affected Systems
HAVELSAN Inc. Geographic Tracking System versions prior to v0.0.2 are affected. Users of the system on those releases must verify their installed version and upgrade if necessary.
Risk and Exploitability
The CVSS score of 9.1 indicates a high severity. Although the EPSS score is not available, the score suggests a high likelihood of exploitation if the flaw remains unpatched. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers would typically need an authenticated session to manipulate an identifier; however, once authenticated, they can reference other users' data by simply altering the key in the request.
OpenCVE Enrichment