No. The reported SSRF in the WorkPlace interface is described as unauthenticated.
The chain uses the /wsproxy WebSocket endpoint to access a locally bound Erlang distribution node, couchdb@127.0.0.1, on port 1050. It completes the Erlang handshake using a hardcoded cookie and obtains command execution as the couchdb user.
An operator can read policy_file.xml and decrypt stored LDAP bind passwords using a static AES key recovered from ASAPPasswordUtil.class. The reported activity then used those credentials and domain-controller machine-account hashes to run DCSync against internal domain controllers, including pass-the-hash authentication.
The reported workflow dropped a standalone Linux build of Impacket secretsdump into /tmp on the appliance before using it against internal domain controllers.