Due to a lack of authentication, it is possible for an unauthenticated user to request data from this endpoint, making the application vulnerable for user enumeration.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NSick Baggage Analytics
APPSickall versionsSick Enterprise Analytics
APPSickall versionsSick Logistic Diagnostic Analytics
APPSickall versionsSick Package Analytics
APPSickall versionsSick Tire Analytics
APPSickall versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2020-2076CRITICAL9.8PL ✓same product
Obejście uwierzytelniania w SICK Package Analytics przez REST API
CVE-2025-49184HIGH7.5same product
A remote unauthorized attacker may gather sensitive information of the application, due to missing authorizati...
CVE-2020-2077HIGH7.5same product
SICK Package Analytics software up to and including version V04.0.0 are vulnerable due to incorrect default pe...
CVE-2025-58580MEDIUM6.5same product
An API endpoint allows arbitrary log entries to be created via POST request. Without sufficient va...
CVE-2025-58581MEDIUM4.3same product
When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class...