CVE-2019-16133: Medium severity weaver eteams oa vulnerability
An issue was discovered in eteams OA v4.0.34. Because the session is not strictly checked, the account names and passwords of all employees in the company can be obtained by an ordinary account. Specifically, the attacker sends a jsessionid value for URIs under app/profile/summary/.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-16133?
CVE-2019-16133 is considered a critical vulnerability due to its potential for unauthorized access to sensitive employee information.
How do I fix CVE-2019-16133?
To fix CVE-2019-16133, update the Weaver Eteams OA software to the latest version that includes the patch for session validation.
What are the implications of CVE-2019-16133?
The implications of CVE-2019-16133 include the risk of data exposure and unauthorized access to user accounts within the affected application.
Who is affected by CVE-2019-16133?
Organizations using Weaver Eteams OA version 4.0.34 are affected by CVE-2019-16133 and should take immediate action to mitigate the risk.
How can CVE-2019-16133 be exploited?
CVE-2019-16133 can be exploited by an attacker who sends a manipulated jsessionid to obtain account names and passwords through the app/profile/summary/ endpoint.