OpenKM Authentication Bypass Vulnerability
BID:51250
Info
OpenKM Authentication Bypass Vulnerability
| Bugtraq ID: | 51250 |
| Class: | Access Validation Error |
| CVE: |
CVE-2012-2315 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 03 2012 12:00AM |
| Updated: | Mar 08 2015 04:04PM |
| Credit: | Cyrill Brunschwiler |
| Vulnerable: |
OpenKM OpenKM 5.1.7 |
| Not Vulnerable: |
OpenKM OpenKM 5.1.8 |
Discussion
OpenKM Authentication Bypass Vulnerability
OpenKM is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to bypass the authentication process and gain unauthorized access to the affected system.
OpenKM 5.1.7 is vulnerable; other versions may also be affected.
OpenKM is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to bypass the authentication process and gain unauthorized access to the affected system.
OpenKM 5.1.7 is vulnerable; other versions may also be affected.
Exploit / POC
OpenKM Authentication Bypass Vulnerability
An attacker can use readily available tools to exploit this issue.
An attacker can use readily available tools to exploit this issue.
Solution / Fix
OpenKM Authentication Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.