The vendor explicitly identifies these products as affected by this CVE.
- SmartClient modules Opcenter QL Home (SC)
- SOA Audit
- SOA Cockpit
- Summary
- The affected application does not enforce mandatory authorization on some functionality level at server side. This could allow an authenticated attacker to gain complete access of the application.
- Remediation
- Update to V2506 or later version
