VulnerabilityModified
CVE-2012-4021
MosP kintai kanri before 4.1.0 does not properly perform authentication, which allows remote authenticated users to impersonate arbitrary user accounts, and consequently obtain sensitive information or modify settings, via unspecified vectors.
MEDIUM 5.5EPSS 1.14%
Does this matter?
Lower severity and a low EPSS score (1.14%). Track it; it rarely justifies an emergency change on its own.
Description
MosP kintai kanri before 4.1.0 does not properly perform authentication, which allows remote authenticated users to impersonate arbitrary user accounts, and consequently obtain sensitive information or modify settings, via unspecified vectors.
- CVSS 2.0
- 5.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:N
- EPSS
- 1.14% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- mosp/kintai kanri
- Source
- vultures@jpcert.or.jp
References
- http://jvn.jp/en/jp/JVN52264310/index.html
- http://jvndb.jvn.jp/jvndb/JVNDB-2012-000097
- http://secunia.com/advisories/51110
- http://www.securityfocus.com/bid/56369
- http://jvn.jp/en/jp/JVN52264310/index.html
- http://jvndb.jvn.jp/jvndb/JVNDB-2012-000097
- http://secunia.com/advisories/51110
- http://www.securityfocus.com/bid/56369
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.