OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly determine the HTTP requests originating IP address, allowing attackers to spoof it using X-Forwarded-For in the header, by supplying localhost address such as 127.0.0.1, effectively bypassing all IP address based access controls.
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Digital_asset_management | Openasset | * | 12.0.19 (including) |