Lucene search

K
prionPRIOn knowledge basePRION:CVE-2015-1498
HistoryFeb 16, 2015 - 3:59 p.m.

Cross site request forgery (csrf)

2015-02-1615:59:00
PRIOn knowledge base
www.prio-n.com
3

7.2 High

AI Score

Confidence

Low

0.698 Medium

EPSS

Percentile

98.0%

Persistent Systems Radia Client Automation does not properly restrict access to certain request, which allows remote attackers to (1) enumerate user accounts via a getUsers request, (2) assign a role to a user account via an addAssigneesToRole request, (3) remove a role from a user account via a removeAssigneesFromRole request, or (4) have other unspecified impact.

7.2 High

AI Score

Confidence

Low

0.698 Medium

EPSS

Percentile

98.0%

Related for PRION:CVE-2015-1498