CVE-2021-36389: High severity yellowfin business intelligence vulnerability
Published Oct 14, 2021
·Updated
In Yellowfin before 9.6.1 it is possible to enumerate and download uploaded images through an Insecure Direct Object Reference vulnerability exploitable by sending a specially crafted HTTP GET request to the page "MIImage.i4".
Affected Software
1 affected component
Yellowfinbi Yellowfin<9.6.1
Event History
Oct 14, 2021
CVE Published
via MITRE·06:27 PM
Data Sourced
via MITRE·06:27 PM
Description
Frequently Asked Questions
1
What is CVE-2021-36389?
CVE-2021-36389 is an Insecure Direct Object Reference vulnerability in Yellowfin before 9.6.1, which allows attackers to enumerate and download uploaded images.
2
How can an attacker exploit CVE-2021-36389?
An attacker can exploit CVE-2021-36389 by sending a specially crafted HTTP GET request to the page "MIImage.i4".
3
Which versions of Yellowfin are affected by CVE-2021-36389?
Yellowfin versions up to and excluding 9.6.1 are affected by CVE-2021-36389.
4
What is the severity of CVE-2021-36389?
CVE-2021-36389 has a severity of 7.5 (High).
5
How do I fix CVE-2021-36389?
To fix CVE-2021-36389, upgrade Yellowfin to version 9.6.1 or later.