An Insecure Direct Object Reference issue exists in the Tyler Odyssey Portal platform before 17.1.20. This may allow an external party to access sensitive case records.
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Link | Tags |
---|---|
https://www.calbar.ca.gov/About-Us/News/Data-Breach-Updates | issue tracking us government resource third party advisory |
https://www.tylertech.com/dataharvest | issue tracking vendor advisory |
https://www.judyrecords.com/what-happened-with-tyler-technologies | exploit third party advisory technical description |
https://www.judyrecords.com/info | third party advisory |
https://news.ycombinator.com/item?id=30502117 | third party advisory |