Corero SecureWatch Managed Services 9.7.2.0020 does not correctly check swa-monitor and cns-monitor user’s privileges, allowing a user to perform actions not belonging to his role.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.