First published: Fri Jul 22 2022(Updated: )
Under certain circumstances an unauthenticated user could access the the web API for Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions prior to 11.0.2 and enumerate users.
Credit: productsecurity@jci.com
Affected Software | Affected Version | How to fix |
---|---|---|
Johnsoncontrols Metasys Application And Data Server | >=10.0<10.1.6 | |
Johnsoncontrols Metasys Application And Data Server | >=11.0<11.0.2 | |
Johnsoncontrols Metasys Extended Application And Data Server | >=10.0<10.1.6 | |
Johnsoncontrols Metasys Extended Application And Data Server | >=11.0<11.0.2 | |
Johnsoncontrols Metasys Open Application Server | >=10.0<10.1.6 | |
Johnsoncontrols Metasys Open Application Server | >=11.0<11.0.2 | |
Johnson Controls, Inc Johnson Controls Metasys ADS, ADX, OAS with MUI | =10 | |
Johnson Controls, Inc Johnson Controls Metasys ADS, ADX, OAS with MUI | =11 |
Update all Metasys ADS/ADX/OAS 10 versions with patch 10.1.6
Update all Metasys ADS/ADX/OAS 11 versions with patch 11.0.2
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-36200.
The severity of CVE-2021-36200 is medium with a severity value of 5.3.
Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions prior to 11.0.2 are affected by CVE-2021-36200.
Under certain circumstances, an unauthenticated user can access the web API for Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions prior to 11.0.2.
If an unauthenticated user accesses the web API for Metasys ADS/ADX/OAS, they can enumerate users.