CVE-2017-9421: Medium severity Accellion kiteworks vulnerability
Authentication Bypass vulnerability in Accellion kiteworks before 2017.01.00 allows remote attackers to execute certain API calls on behalf of a web user using a gathered token via a POST request to /oauth/token.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-9421?
CVE-2017-9421 is an Authentication Bypass vulnerability in Accellion kiteworks before version 2017.01.00.
How does the Authentication Bypass vulnerability in Accellion kiteworks work?
The vulnerability allows remote attackers to execute certain API calls on behalf of a web user using a gathered token via a POST request to /oauth/token.
What is the severity of CVE-2017-9421?
CVE-2017-9421 has a severity value of 6.5 which is considered medium.
How can I fix the Authentication Bypass vulnerability in Accellion kiteworks?
To fix the vulnerability, update Accellion kiteworks to version 2017.01.00 or later.
Is there any additional information about CVE-2017-9421?
Yes, you can find more information about CVE-2017-9421 at the following reference: <a href='https://github.com/jer1nj0y/Vulns/blob/master/Kiteworks%20Vulnerability'>https://github.com/jer1nj0y/Vulns/blob/master/Kiteworks%20Vulnerability</a>