go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

FLOWRING Agentflow BPM - Broken Access Control

TVN ID TVN-202210012
CVE ID CVE-2022-39038
CVSS 8.8 (High)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products FLOWRING Agentflow BPM V.4.0.0.1183.552
Description Agentflow BPM enterprise management system has improper authentication. A remote attacker with general user privilege can change the name of the user account to acquire arbitrary account privilege, and access, manipulate system or disrupt service.
Solution Contact tech support from FLOWRING
Credit Alan Chung、Kaibro (DEVCORE)
Public Date 2022-11-10
Top