Description
The product implements a Security Token mechanism to differentiate what actions are allowed or disallowed when a transaction originates from an entity. However, the Security Tokens generated in the system are incorrect.
CVE vulnerabilities with CWE-1270 (10)
9.8
CVSS
CRITICAL
CVE-2023-2882
pub. 2023-05-25
9.8
CVSS
CRITICAL
CVE-2022-31122
pub. 2022-10-18
9.4
CVSS
CRITICAL
CVE-2023-32188
pub. 2024-10-16
9.4
CVSS
CRITICAL
CVE-2023-22644
pub. 2023-09-20
8.8
CVSS
HIGH
CVE-2026-49499
pub. 2026-07-22
8.1
CVSS
HIGH
CVE-2026-54593
pub. 2026-07-28
6.8
CVSS
MEDIUM
CVE-2025-59698
pub. 2025-12-02
6.0
CVSS
MEDIUM
CVE-2026-19636
pub. 2026-08-14
4.3
CVSS
MEDIUM
CVE-2026-15831
pub. 2026-07-29
4.3
CVSS
MEDIUM
CVE-2023-30524
pub. 2023-04-12