First published: Fri Dec 17 2021(Updated: )
TCMAN GIM does not perform an authorization check when trying to access determined resources. A remote attacker could exploit this vulnerability to access URL that require privileges without having them. The exploitation of this vulnerability might allow a remote attacker to obtain sensible information.
Credit: cve-coordination@incibe.es cve-coordination@incibe.es
Affected Software | Affected Version | How to fix |
---|---|---|
TCMAN GIM | =8.0 | |
TCMAN GIM | =11.0 |
This vulnerability has been solved by TCMAN in GIM v8.0.1 Release 31734
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-40853 is a vulnerability in TCMAN GIM that allows remote attackers to access privileged resources without authorization.
CVE-2021-40853 has a severity of 7.2 (high).
TCMAN GIM versions 8.0 and 11.0 are affected by CVE-2021-40853.
An attacker can exploit CVE-2021-40853 to access URLs that require privileges without having them, potentially obtaining sensitive information.
It is recommended to apply the latest security patches or updates provided by TCMAN GIM to mitigate CVE-2021-40853.