CVE-2018-17791
Summary
| CVE | CVE-2018-17791 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-08-21 20:15:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | Newgen OmniFlow Intelligent Business Process Suite (iBPS) 7.0 has an "improper server side validation" vulnerability where client-side validations are tampered, and inappropriate information is stored on the server side and fetched from the server every time the user visits the D, creating business confusion. In the worst case, all available resources are consumed while processing the data, resulting in unavailability of the service to legitimate users. This occurs because non-editable parameters can be modified by manually editing a disabled form field within the developer options. |
Risk And Classification
Problem Types: CWE-669
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Newgensoft | Omniflow Intelligent Business Process Suite | 7.0 | All | All | All |
| Application | Newgensoft | Omniflow Intelligent Business Process Suite | 7.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| OmniDoc 7.0 Input Validation ≈ Packet Storm | MISC | packetstormsecurity.com | Third Party Advisory, VDB Entry |
| CVE-2018-17791 ≈ Packet Storm | MISC | packetstormsecurity.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.