Insufficient access control in the web interface of ABB Asset Suite versions 9.0 to 9.3, 9.4 prior to 9.4.2.6, 9.5 prior to 9.5.3.2 and 9.6.0 enables full access to directly referenced objects. An attacker with knowledge of a resource's URL can access the resource directly.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: ABB

Published: 2020-02-17T18:40:38

Updated: 2020-03-12T22:28:21

Reserved: 2019-11-15T00:00:00


Link: CVE-2019-18998

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-02-17T19:15:12.150

Modified: 2023-05-16T20:06:09.550


Link: CVE-2019-18998

JSON object: View

cve-icon Redhat Information

No data.