Source |
CVE Liste |
Identifiant |
8313711 |
Date de publication |
2023-02-27 13:15:10 (vue: 2023-02-27 16:06:59) |
Titre |
CVE-2022-34908 |
Texte |
An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It possesses an authentication mechanism; however, some features do not require any token or cookie in a request. Therefore, an attacker may send a simple HTTP request to the right endpoint, and obtain authorization to retrieve application data. |
Notes |
|
Envoyé |
Oui |
Condensat |
2022 34908 a4n android any application aremis attacker authentication authorization cookie cve data discovered endpoint features however http issue may mechanism; nomad not obtain possesses request require retrieve right send simple some therefore token |
Tags |
|
Stories |
|
Move |
|