An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It possesses an authentication mechanism; however, some features do not require any token or cookie in a request. Therefore, an attacker may send a simple HTTP request to the right endpoint, and obtain authorization to retrieve application data.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Link | Tags |
---|---|
https://www.aremis.com/en_GB/welcome | not applicable |
https://excellium-services.com/cert-xlm-advisory/CVE-2022-34908 | third party advisory |