SB2024070333 - Multiple vulnerabilities in Talya Informatics Travel APPS
Published: July 3, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Improper access control (CVE-ID: CVE-2024-1153)
The vulnerability allows a local attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. An attacker with physical access can bypass implemented security restrictions and obtain sensitive information
2) Authorization bypass through user-controlled key (CVE-ID: CVE-2024-1107)
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to authorization bypass through user-controlled key. A remote user can send a specially crafted request and bypass authorization.
Remediation
Install update from vendor's website.