CVE-2024-27455

In the Bentley ALIM Web application, certain configuration settings can cause exposure of a user's ALIM session token when the user attempts to download files. This is fixed in Assetwise ALIM Web 23.00.04.04 and Assetwise Information Integrity Server 23.00.02.03.
Configurations

No configuration.

History

14 Aug 2024, 15:35

Type Values Removed Values Added
CWE CWE-488
CWE-613
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1

26 Mar 2024, 16:15

Type Values Removed Values Added
Summary
  • (es) En la aplicación web Bentley ALIM, ciertos ajustes de configuración pueden provocar la exposición del token de sesión ALIM de un usuario cuando el usuario intenta descargar archivos. Esto se solucionó en Assetwise ALIM Web 23.00.02.03 y Assetwise Information Integrity Server 23.00.04.04.
Summary (en) In the Bentley ALIM Web application, certain configuration settings can cause exposure of a user's ALIM session token when the user attempts to download files. This is fixed in Assetwise ALIM Web 23.00.02.03 and Assetwise Information Integrity Server 23.00.04.04. (en) In the Bentley ALIM Web application, certain configuration settings can cause exposure of a user's ALIM session token when the user attempts to download files. This is fixed in Assetwise ALIM Web 23.00.04.04 and Assetwise Information Integrity Server 23.00.02.03.

26 Feb 2024, 16:32

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-26 16:28

Updated : 2024-08-14 15:35


NVD link : CVE-2024-27455

Mitre link : CVE-2024-27455

CVE.ORG link : CVE-2024-27455


JSON object : View

Products Affected

No product.

CWE
CWE-488

Exposure of Data Element to Wrong Session

CWE-613

Insufficient Session Expiration