The xml-rpc server in Roundup 1.4.4 does not check property permissions, which allows attackers to bypass restrictions and edit or read restricted properties via the (1) list, (2) display, and (3) set methods.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.