#VU26058 Authorization bypass through user-controlled key in Asset Suite - CVE-2019-18998
Published: March 13, 2020
Asset Suite
ABB
Description
The vulnerability allows a remote user to gain unauthorized access to sensitive information in the application.
The vulnerability exist due to improper access controls used to limit user access to resources. A
remote user who knows or discovered the URL for a resource they do not have
permissions to, they would be able to access the resource by browsing
directly to the URL.