ARC Informatique PcVue prior to version 12.0.17 is vulnerable to a denial-of-service attack due to the ability of an unauthorized user to modify information used to validate messages sent by legitimate web clients. This issue also affects third-party systems based on the Web Services Toolkit.
The product defines a public method that reads or modifies a private variable.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Pcvue | Pcvuesolutions | 8.10 (including) | 12.0.17 (excluding) |