Vulnerabilities > CVE-2021-44836 - Authorization Bypass Through User-Controlled Key vulnerability in Deltarm Delta RM 1.2
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
NONE Integrity impact
LOW Availability impact
NONE Summary
An issue was discovered in Delta RM 1.2. The /risque/risque/workflow/reset endpoint is lacking access controls, and it is possible for an unprivileged user to reopen a risk with a POST request, using the risqueID parameter to identify the risk to be re-opened.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |