Impact
The vulnerability allows any authenticated user to invoke any DWR method by placing the target class name and method into the POST body, thereby bypassing the URL‑based Spring Security controls. The flaw is a classic authority and access control weakness (CWE-639) where the application trusts request parameters over established access policies. An attacker with legitimate credentials can therefore execute restricted server‑side logic, potentially exposing, modifying, or deleting protected data or performing other privileged operations.
Affected Systems
Scada‑LTS version 2.8.1‑release‑candidate build 0 is affected. No other vendor or product versions were identified as vulnerable.
Risk and Exploitability
The CVSS score of 8.8 marks it as high severity and the EPSS score of < 1 % indicates a low likelihood of widespread exploitation at this time. It is not listed in the CISA KEV catalog. The attack requires a valid authenticated session and access to a DWR URL that the attacker can target. Because the application does not validate request origins when crossDomainSessionSecurity is disabled, a malicious actor can send a crafted POST body to any accessible DWR endpoint and direct the call to a restricted class, enabling the exploitation of multiple downstream weaknesses.
OpenCVE Enrichment