First published: Wed Dec 01 2021(Updated: )
Sunnet eHRD has broken access control vulnerability, which allows a remote attacker to access account management page after being authenticated as a general user, then perform privilege escalation to execute arbitrary code and control the system or interrupt services.
Credit: twcert@cert.org.tw twcert@cert.org.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Sun Enterprise Resource Planning (ERP) | =8 | |
Sun Enterprise Resource Planning (ERP) | =9 |
Update Sunnet eHRD version to 10
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-43359 has a high severity rating due to the potential for privilege escalation and arbitrary code execution.
To remediate CVE-2021-43359, it is recommended to update to the latest version of Sun eHRD that addresses this vulnerability.
CVE-2021-43359 affects Sun eHRD versions 8 and 9.
An attacker exploiting CVE-2021-43359 can access the account management page and execute arbitrary code, potentially taking control of the system.
CVE-2021-43359 can be exploited remotely after initial user authentication.