An issue was discovered in AlertEnterprise Guardian 4.1.14.2.2.1. One can bypass manager approval by changing the user ID in a Request%20Building%20Access requestSubmit API call.
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.