Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40694
HistoryMay 26, 2023 - 4:43 a.m.

Insecure Direct Object References (IDOR)

2023-05-2604:43:48
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
16
insecure direct object references
improper authentication
file access
directory access
application cancellation

EPSS

0.002

Percentile

61.1%

manager-workflow is vulnerable to Insecure Direct Object References (IDOR). The vulnerability exists due to improper authentication mechanism used in ProcessServiceImpl.java when operating a workflow, which allows an attacker to access files or directories and cancel an application that doesn’t belongs to them.

EPSS

0.002

Percentile

61.1%