CVE-2012-2455

Advanced Productivity Software DTE Axiom before 12.3.3 does not validate the registration ID, which allows remote attackers to bypass authentication and read or modify data about users, customers, and projects via unspecified vectors.
Configurations

Configuration 1 (hide)

cpe:2.3:a:advance_productivity_software:dte_axiom:*:*:*:*:*:*:*:*

History

21 Nov 2024, 01:39

Type Values Removed Values Added
References () http://seclists.org/fulldisclosure/2012/Sep/62 - () http://seclists.org/fulldisclosure/2012/Sep/62 -
References () http://secunia.com/advisories/50508 - Vendor Advisory () http://secunia.com/advisories/50508 - Vendor Advisory
References () http://www.osvdb.org/85499 - () http://www.osvdb.org/85499 -

Information

Published : 2012-11-10 00:55

Updated : 2024-11-21 01:39


NVD link : CVE-2012-2455

Mitre link : CVE-2012-2455

CVE.ORG link : CVE-2012-2455


JSON object : View

Products Affected

advance_productivity_software

  • dte_axiom
CWE
CWE-264

Permissions, Privileges, and Access Controls