The doFilter method in UrlAccessController in HPE Intelligent Management Center (iMC) PLAT 7.2 E0403P06 allows remote bypass of authentication via unspecified strings in a URI.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/101224 | vdb entry third party advisory |
http://www.securityfocus.com/bid/96815 | vdb entry third party advisory |
http://www.zerodayinitiative.com/advisories/ZDI-17-161/ | vdb entry third party advisory |
http://www.securitytracker.com/id/1037983 | vdb entry third party advisory |
https://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbhf03716en_us | vendor advisory |