#VU49002 Improper access control in Digital Asset Management - CVE-2020-28856
Published: December 14, 2020 / Updated: December 15, 2020
Digital Asset Management
OpenAsset
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the application does not correctly determine the HTTP request's originating IP address. A remote attacker can bypass all IP address based access controls configured for the software.