CVE-2024-27455

In the Bentley ALIM Web application, certain configuration settings can cause exposure of a user's ALIM session token when the user attempts to download files. This is fixed in Assetwise ALIM Web 23.00.04.04 and Assetwise Information Integrity Server 23.00.02.03.
Configurations

No configuration.

History

14 Aug 2024, 15:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
CWE CWE-613
CWE-488

26 Mar 2024, 16:15

Type Values Removed Values Added
Summary (en) In the Bentley ALIM Web application, certain configuration settings can cause exposure of a user's ALIM session token when the user attempts to download files. This is fixed in Assetwise ALIM Web 23.00.02.03 and Assetwise Information Integrity Server 23.00.04.04. (en) In the Bentley ALIM Web application, certain configuration settings can cause exposure of a user's ALIM session token when the user attempts to download files. This is fixed in Assetwise ALIM Web 23.00.04.04 and Assetwise Information Integrity Server 23.00.02.03.

26 Feb 2024, 16:32

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-26 16:28

Updated : 2024-08-14 15:35


NVD link : CVE-2024-27455

Mitre link : CVE-2024-27455

CVE.ORG link : CVE-2024-27455


JSON object : View

Products Affected

No product.

CWE
CWE-488

Exposure of Data Element to Wrong Session

CWE-613

Insufficient Session Expiration