CVE-2020-8494
Summary
| CVE | CVE-2020-8494 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-01-30 22:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | In Kronos Web Time and Attendance (webTA) 3.8.x and later 3.x versions before 4.0, the com.threeis.webta.H402editUser servlet allows an attacker with Timekeeper, Master Timekeeper, or HR Admin privileges to gain unauthorized administrative privileges within the application via the emp_id, userid, pw1, pw2, supervisor, and timekeeper parameters. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Kronos | Web Time And Attendance | All | All | All | All |
| Application | Kronos | Web Time And Attendance | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| WebTA - Employee Time Tracking for government | Kronos | MISC | www.kronos.com | Product, Vendor Advisory |
| CVE-2020-8494: Authenticated Remote Privilege Escalation in Kronos Web Time and Attendance (webTA) | MISC | www.nolanbkennedy.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.