Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch and Apps Portal before 19.2.0.3 or 19.2.0.20240814, has incorrect authorization controls for the Admin functionality on the ThreatAvert Policy page. An authenticated user can navigate directly to the /#app/intelligence/threatAvertPolicies URI and disable policy enforcement.
References
Link | Resource |
---|---|
https://www.akamai.com/global-services/support/vulnerability-reporting | Product |
https://notes.netbytesec.com/2024/11/cve-2024-45164-broken-access-control.html | Exploit Mitigation Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
06 Nov 2024, 15:51
Type | Values Removed | Values Added |
---|---|---|
References | () https://notes.netbytesec.com/2024/11/cve-2024-45164-broken-access-control.html - Exploit, Mitigation, Third Party Advisory | |
References | () https://www.akamai.com/global-services/support/vulnerability-reporting - Product | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.1 |
CPE | cpe:2.3:a:akamai:secure_internet_access_enterprise_threatavert:19.2.0.2:*:*:*:*:*:*:* | |
First Time |
Akamai secure Internet Access Enterprise Threatavert
Akamai |
|
CWE | CWE-863 |
04 Nov 2024, 14:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-11-04 14:15
Updated : 2024-11-06 17:35
NVD link : CVE-2024-45164
Mitre link : CVE-2024-45164
JSON object : View
Products Affected
akamai
- secure_internet_access_enterprise_threatavert
CWE
CWE-863
Incorrect Authorization