Assigner | BT |
Reserved | 2024-06-10 |
Published | 2024-06-11 |
Updated | 2024-06-11 |
Description
A low severity vulnerability in BIPS has been identified where an attacker with high privileges or a compromised high privilege account can overwrite Read-Only smart rules via a specially crafted API request.
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N |
Problem types
CWE-290 Authentication Bypass by Spoofing
Product status
24.1.0 before 24.1.1
23.3.0 before 23.3.0.959
23.2.0 before 23.2.0.1293
References
https://www.beyondtrust.com/trust-center/security-advisories/bt24-07