Under certain circumstances improper privilege management in Metasys ADS/ADX/OAS servers versions 10 and 11 could allow an authenticated user to elevate their privileges to administrator.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Metasys_application_and_data_server | Johnsoncontrols | 10.0 (including) | 10.1.5 (excluding) |
Metasys_application_and_data_server | Johnsoncontrols | 11.0 (including) | 11.0.2 (excluding) |
Metasys_extended_application_and_data_server | Johnsoncontrols | 10.0 (including) | 10.1.5 (excluding) |
Metasys_extended_application_and_data_server | Johnsoncontrols | 11.0 (including) | 11.0.2 (excluding) |
Metasys_open_application_server | Johnsoncontrols | 10.0 (including) | 10.1.5 (excluding) |
Metasys_open_application_server | Johnsoncontrols | 11.0 (including) | 11.0.2 (excluding) |