In the Bentley ALIM Web application, certain configuration settings can cause exposure of a user's ALIM session token when the user attempts to download files. This is fixed in Assetwise ALIM Web 23.00.04.04 and Assetwise Information Integrity Server 23.00.02.03.
Specific configuration settings in the Bentley ALIM Web application cause the user's session token to be exposed when initiating a file download operation. This results from improper session data management (CWE-488 — exposure of data between sessions) and insufficient session protection (CWE-613 — insufficient session timeout). The intercepted token can be used by an unauthorized person to impersonate a legitimate user.
An attacker who intercepts the session token can gain full access to the victim's account in the ALIM Web system, leading to disclosure of confidential data and the ability to modify it (high data confidentiality and integrity).
Software must be updated to Assetwise ALIM Web version 23.00.04.04 or later and Assetwise Information Integrity Server 23.00.02.03 or later. Details are available in the official Bentley advisory at https://www.bentley.com/advisories/be-2024-0001/
Bentley ALIM Web (patch introduced in Assetwise ALIM Web 23.00.04.04) and Assetwise Information Integrity Server (patch introduced in version 23.00.02.03). Earlier versions of these products are vulnerable.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N