Description
A low severity vulnerability in BIPS has been identified where an attacker with high privileges or a compromised high privilege account can overwrite Read-Only smart rules via a specially crafted API request.
Problem types
CWE-290 Authentication Bypass by Spoofing
Product status
24.1.0 (custom) before 24.1.1
23.3.0 (custom) before 23.3.0.959
23.2.0 (custom) before 23.2.0.1293
References
www.beyondtrust.com/trust-center/security-advisories/bt24-07
www.beyondtrust.com/trust-center/security-advisories/bt24-07