7.5

CVE-2022-26665

Exploit
An Insecure Direct Object Reference issue exists in the Tyler Odyssey Portal platform before 17.1.20. This may allow an external party to access sensitive case records.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
TylertechOdyssey Portal Version < 17.1.20
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.8% 0.756
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-639 Authorization Bypass Through User-Controlled Key

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

https://news.ycombinator.com/item?id=30502117
Third Party Advisory
https://www.calbar.ca.gov/About-Us/News/Data-Breach-Updates
Third Party Advisory
US Government Resource
Issue Tracking
https://www.judyrecords.com/info
Third Party Advisory
https://www.judyrecords.com/what-happened-with-tyler-technologies
Third Party Advisory
Exploit
Technical Description
https://www.tylertech.com/dataharvest
Vendor Advisory
Issue Tracking