Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch and Apps Portal before 19.2.0.3 or 19.2.0.20240814, has incorrect authorization controls for the Admin functionality on the ThreatAvert Policy page. An authenticated user can navigate directly to the /#app/intelligence/threatAvertPolicies URI and disable policy enforcement.
Metrics
Affected Vendors & Products
References
History
Wed, 06 Nov 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-732 | |
| Metrics |
cvssV3_1
|
ssvc
|
Wed, 06 Nov 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Akamai
Akamai secure Internet Access Enterprise Threatavert |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:akamai:secure_internet_access_enterprise_threatavert:19.2.0.2:*:*:*:*:*:*:* | |
| Vendors & Products |
Akamai
Akamai secure Internet Access Enterprise Threatavert |
|
| Metrics |
cvssV3_1
|
Mon, 04 Nov 2024 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch and Apps Portal before 19.2.0.3 or 19.2.0.20240814, has incorrect authorization controls for the Admin functionality on the ThreatAvert Policy page. An authenticated user can navigate directly to the /#app/intelligence/threatAvertPolicies URI and disable policy enforcement. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2024-11-04T00:00:00
Updated: 2024-11-06T16:18:38.490Z
Reserved: 2024-08-22T00:00:00
Link: CVE-2024-45164
Updated: 2024-11-06T16:18:32.432Z
Status : Modified
Published: 2024-11-04T14:15:14.677
Modified: 2024-11-06T17:35:33.437
Link: CVE-2024-45164
No data.