CVE-2021-44837
- EPSS 0.23%
- Veröffentlicht 19.01.2022 14:15:07
- Zuletzt bearbeitet 21.11.2024 06:31:35
An issue was discovered in Delta RM 1.2. It is possible for an unprivileged user to access the same information as an admin user regarding the risk creation information in the /risque/administration/referentiel/json/create/categorie endpoint, using t...
CVE-2021-44836
- EPSS 0.16%
- Veröffentlicht 18.01.2022 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:31:35
An issue was discovered in Delta RM 1.2. The /risque/risque/workflow/reset endpoint is lacking access controls, and it is possible for an unprivileged user to reopen a risk with a POST request, using the risqueID parameter to identify the risk to be ...
- EPSS 0.23%
- Veröffentlicht 18.01.2022 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:31:35
An issue was discovered in Delta RM 1.2. Using the /risque/risque/ajax-details endpoint, with a POST request indicating the risk to access with the id parameter, it is possible for users to access risks of other companies.
CVE-2021-44839
- EPSS 0.15%
- Veröffentlicht 18.01.2022 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:31:35
An issue was discovered in Delta RM 1.2. It is possible to request a new password for any other account using the account ID. Using the /listes/DTsendmaildata/adm_utilisateur/send-mail.json endpoint, a user can send a JSON array with user IDs that wi...
- EPSS 0.19%
- Veröffentlicht 18.01.2022 19:15:09
- Zuletzt bearbeitet 21.11.2024 06:31:35
An issue was discovered in Delta RM 1.2. Using an privileged account, it is possible to edit, create, and delete risk labels, such as Criticality and Priority Indication labels. By using the /core/table/query endpoint, and by using a POST request and...