First published: Tue Sep 14 2021(Updated: )
A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.8), Teamcenter V13.0 (All versions < V13.0.0.7), Teamcenter V13.1 (All versions < V13.1.0.5), Teamcenter V13.2 (All versions < 13.2.0.2). The affected application contains Insecure Direct Object Reference (IDOR) vulnerability that allows an attacker to use user-supplied input to access objects directly.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Teamcenter Visualization | >=12.4.0<12.4.0.8 | |
Siemens Teamcenter Visualization | >=13.0.0<13.0.0.7 | |
Siemens Teamcenter Visualization | >=13.1.0<13.1.0.5 | |
Siemens Teamcenter Visualization | >=13.2.0<13.2.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-40355 has a high severity rating due to its potential for exploitation through Insecure Direct Object Reference (IDOR).
To fix CVE-2021-40355, upgrade to Teamcenter versions V12.4.0.8, V13.0.0.7, V13.1.0.5, or V13.2.0.2 or later.
CVE-2021-40355 affects Teamcenter versions V12.4 (below 12.4.0.8), V13.0 (below 13.0.0.7), V13.1 (below 13.1.0.5), and V13.2 (below 13.2.0.2).
CVE-2021-40355 is classified as an Insecure Direct Object Reference (IDOR) vulnerability.
Yes, exploitation of CVE-2021-40355 can potentially lead to unauthorized access and data exposure.