logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2024-45164

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2024-45164

Description:
Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch and Apps Portal before 19.2.0.3 or 19.2.0.20240814, has incorrect authorization controls for the Admin functionality on the ThreatAvert Policy page. An authenticated user can navigate directly to the /#app/intelligence/threatAvertPolicies URI and disable policy enforcement.
Last updated date:
11/06/2024
Type:
exploit
Confidence:
HIGH
Date of publishing:
11/06/2024
Reference url to background

https://notes.netbytesec.com/2024/11/cve-2024-45164-broken-access-control.html

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy