The vendor explicitly identifies these products as affected by this CVE.
- SiPass integrated
- Summary
- Affected server applications contains a broken access control vulnerability. The authorization mechanism lacks sufficient server-side checks, allowing an attacker to execute a specific API request. Successful exploitation allows an attacker to potentially manipulate data belonging to other users.
- Remediation
- Update to V3.0 or later version
