CVE-2019-6716
21.03.2019, 16:01
An unauthenticated Insecure Direct Object Reference (IDOR) in Wicket Core in LogonBox Nervepoint Access Manager 2013 through 2017 allows a remote attacker to enumerate internal Active Directory usernames and group names, and alter back-end server jobs (backup and synchronization jobs), which could allow for the possibility of a Denial of Service attack via a modified jobId parameter in a runJob.html GET request.Enginsight
Vendor | Product | Version |
---|---|---|
logonbox | nervepoint_access_manager | 1.2:rg10 |
logonbox | nervepoint_access_manager | 1.2:rg3 |
logonbox | nervepoint_access_manager | 1.2:rg4 |
logonbox | nervepoint_access_manager | 1.2:rg5 |
logonbox | nervepoint_access_manager | 1.2:rg6 |
logonbox | nervepoint_access_manager | 1.2:rg7 |
logonbox | nervepoint_access_manager | 1.2:rg8 |
logonbox | nervepoint_access_manager | 1.2:rg9 |
logonbox | nervepoint_access_manager | 1.3:rg |
logonbox | nervepoint_access_manager | 1.3:rg1 |
logonbox | nervepoint_access_manager | 1.3:rg2 |
logonbox | nervepoint_access_manager | 1.3:rg3 |
logonbox | nervepoint_access_manager | 1.3:rg4 |
logonbox | nervepoint_access_manager | 1.3:rg5 |
logonbox | nervepoint_access_manager | 1.3:rg6 |
logonbox | nervepoint_access_manager | 1.3:rg7 |
logonbox | nervepoint_access_manager | 1.3:rg8 |
logonbox | nervepoint_access_manager | 1.4:rg |
logonbox | nervepoint_access_manager | 1.4:rg1 |
logonbox | nervepoint_access_manager | 1.4:rg2 |
logonbox | nervepoint_access_manager | 1.4:rg3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References