An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a local attacker to perform an Authentication Bypass attack due to improperly implemented security checks for standard authentication mechanisms
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
This weakness has been deprecated because it covered redundant concepts already described in CWE-287.
Link | Tags |
---|---|
http://caterease.com | product |
http://horizon.com | not applicable |
https://vuldb.com/?id.273368 | vdb entry permissions required |
https://packetstormsecurity.com/files/179892/Caterease-Software-SQL-Injection-Command-Injection-Bypass.html | third party advisory |