BTS is affected by information disclosure vulnerability where mobile network operator personnel connected over BTS Web Element Manager, regardless of the access privileges, having a possibility to read BTS service operation details performed by Nokia Care service personnel via SSH.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.