Improper access control in Retail Operations and Counterparty Settlement and Billing (CSB) - CVE-2021-35528
Published: December 1, 2021
Vulnerability identifier: #VU58463
CSH Severity: Low
CVSS v4: 4.5 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N]
CVE-ID: CVE-2021-35528
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A local administrator can bypass implemented security restrictions and gain unauthorized access to the application.
Affected software
Retail Operations
Counterparty Settlement and Billing (CSB)
Counterparty Settlement and Billing (CSB)
How to mitigate CVE-2021-35528
Install updates from vendor's website.
Retail Operations - update to 5.7.3.1
Counterparty Settlement and Billing (CSB) - update to 5.7.3.1
Counterparty Settlement and Billing (CSB) - update to 5.7.3.1