Description
An authentication bypass vulnerability exists which allows an unauthenticated attacker to control administrator backup functions, leading to compromise of passwords, secrets, and application session tokens stored by the Unified PAM.
Problem types
CWE-306 Missing Authentication for Critical Function
Product status
9.0.*
Credits
Aaron Herndon, Principal Security Consultant, and Marcus Chang, Security Consultant, both of Rapid7.
References
www.rapid7.com/...m-multiple-critical-vulnerabilities-fixed/