Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch and Apps Portal before 19.2.0.3 or 19.2.0.20240814, has incorrect authorization controls for the Admin functionality on the ThreatAvert Policy page. An authenticated user can navigate directly to the /#app/intelligence/threatAvertPolicies URI and disable policy enforcement.
Metrics
Affected Vendors & Products
References
History
Wed, 06 Nov 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-732 | |
Metrics |
cvssV3_1
|
ssvc
|
Wed, 06 Nov 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Akamai
Akamai secure Internet Access Enterprise Threatavert |
|
Weaknesses | CWE-863 | |
CPEs | cpe:2.3:a:akamai:secure_internet_access_enterprise_threatavert:19.2.0.2:*:*:*:*:*:*:* | |
Vendors & Products |
Akamai
Akamai secure Internet Access Enterprise Threatavert |
|
Metrics |
cvssV3_1
|
Mon, 04 Nov 2024 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch and Apps Portal before 19.2.0.3 or 19.2.0.20240814, has incorrect authorization controls for the Admin functionality on the ThreatAvert Policy page. An authenticated user can navigate directly to the /#app/intelligence/threatAvertPolicies URI and disable policy enforcement. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-11-06T16:18:38.490Z
Reserved: 2024-08-22T00:00:00
Link: CVE-2024-45164

Updated: 2024-11-06T16:18:32.432Z

Status : Modified
Published: 2024-11-04T14:15:14.677
Modified: 2024-11-06T17:35:33.437
Link: CVE-2024-45164

No data.