What the vulnerability does
01Description
Access Control vulnerability in Prism IT Systems User Rights Access Manager allows . This issue affects User Rights Access Manager: from n/a through 1.1.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
What the vulnerability does
Access Control vulnerability in Prism IT Systems User Rights Access Manager allows . This issue affects User Rights Access Manager: from n/a through 1.1.2.
Explanation of Vulnerability in Simple Terms
User Rights Access Manager versions up to 1.1.2 lack proper authorization checks, allowing authenticated users to disrupt service availability. An attacker with low-level credentials can trigger a denial-of-service condition without user interaction. The vulnerability affects the authorization logic that should restrict access to sensitive operations.
What an attacker can do
Disrupt service availability by triggering a denial-of-service condition.
Potential impact on your site
Legitimate users may experience service interruptions if an authenticated attacker exploits this flaw.
Conditions required to exploit
Attacker must have a valid user account with low-level privileges.
Key dates
External resources
Related vulnerabilities