CVE Vulnerabilities

CVE-2023-5830

Improper Authentication

Published: Oct 27, 2023 | Modified: Apr 11, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability classified as critical has been found in ColumbiaSoft Document Locator. This affects an unknown part of the file /api/authentication/login of the component WebTools. The manipulation of the argument Server leads to improper authentication. It is possible to initiate the attack remotely. Upgrading to version 7.2 SP4 and 2021.1 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-243729 was assigned to this vulnerability.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Document_locator Documentlocator * 7.2 (excluding)
Document_locator Documentlocator 7.2 (including) 7.2 (including)
Document_locator Documentlocator 7.2-sp3 (including) 7.2-sp3 (including)
Document_locator Documentlocator 21 (including) 21 (including)

Potential Mitigations

References