CVE-2021-36388: High severity yellowfin business intelligence vulnerability
In Yellowfin before 9.6.1 it is possible to enumerate and download users profile pictures through an Insecure Direct Object Reference vulnerability exploitable by sending a specially crafted HTTP GET request to the page "MIIAvatarImage.i4".
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-36388?
CVE-2021-36388 is a vulnerability in Yellowfin before 9.6.1 that allows an attacker to enumerate and download users' profile pictures through an Insecure Direct Object Reference vulnerability.
How can the CVE-2021-36388 vulnerability be exploited?
The CVE-2021-36388 vulnerability in Yellowfin can be exploited by sending a specially crafted HTTP GET request to the 'MIIAvatarImage.i4' page.
What is the severity of CVE-2021-36388?
The severity of CVE-2021-36388 is high, with a CVSS severity score of 7.5.
What is the affected software version of CVE-2021-36388?
The affected software version of CVE-2021-36388 is Yellowfin before 9.6.1.
How can I fix the CVE-2021-36388 vulnerability?
To fix the CVE-2021-36388 vulnerability, it is recommended to upgrade Yellowfin to version 9.6.1 or later.