Missing Authentication for Critical Function in Fsas Technologies products - CVE-2024-33622

 

Missing Authentication for Critical Function in Fsas Technologies products - CVE-2024-33622

Published: June 18, 2024


Vulnerability identifier: #VU92199
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-33622
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to missing authentication for critical function. A remote user can obtaion sensitive information and alter the information stored in the database.


Affected software

FUJITSU Business Application ID Link Manager II
FUJITSU Software TIME CREATOR ID Link Manager SaaS
FUJITSU Software ID Link Manager
FUJITSU Software TIME CREATOR ID Link Manager

How to mitigate CVE-2024-33622

Install updates from vendor's website.


External References

Related Security Bulletins