A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.85 (All versions), Siveillance Identity V1.5 (All versions), Siveillance Identity V1.6 (All versions < V1.6.284.0). Affected applications insufficiently limit the access to the internal activity feed database. This could allow an unauthenticated remote attacker to read, modify or delete activity feed entries.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NSiemens Sipass Integrated
APPSiemens2.762.802.85Siemens Siveillance Identity
APPSiemens1.51.6 – 1.6.280.0
Related vulnerabilities
Spring4Shell — RCE przez data binding w Spring MVC/WebFlux na JDK 9+
Apache Log4j: niekompletna naprawa CVE-2021-44228 — RCE przez JNDI Lookup
Apache Log4j2 Log4Shell — RCE przez podatną funkcję JNDI lookup
Auth Bypass w Siemens SiPass/Siveillance — nieautoryzowany dostęp do usługi uwierzytelniania
Pominięcie uwierzytelnienia w Siemens SiPass Integrated — dostęp administracyjny