Description
Improper Authentication (CWE-287) in the LDAP authentication engine in AxxonSoft Axxon One (C-Werk) 2.0.2 and earlier on Windows allows a remote authenticated user to be denied access or misassigned roles via incorrect evaluation of nested LDAP group memberships during login.
Problem types
CWE-287: Improper Authentication
Product status
Any version
Credits
Resolved internally by the AxxonSoft QA and directory integration teams.
References
www.axxonsoft.com/...y-disclosure-policy/security-advisories