First published: Thu May 24 2018(Updated: )
Authentication Bypass vulnerability in Accellion kiteworks before 2017.01.00 allows remote attackers to execute certain API calls on behalf of a web user using a gathered token via a POST request to /oauth/token.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Accellion Kiteworks | <2017.01.00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9421 is an Authentication Bypass vulnerability in Accellion kiteworks before version 2017.01.00.
The vulnerability allows remote attackers to execute certain API calls on behalf of a web user using a gathered token via a POST request to /oauth/token.
CVE-2017-9421 has a severity value of 6.5 which is considered medium.
To fix the vulnerability, update Accellion kiteworks to version 2017.01.00 or later.
Yes, you can find more information about CVE-2017-9421 at the following reference: <a href='https://github.com/jer1nj0y/Vulns/blob/master/Kiteworks%20Vulnerability'>https://github.com/jer1nj0y/Vulns/blob/master/Kiteworks%20Vulnerability</a>