CVE-2024-27455

In the Bentley ALIM Web application, certain configuration settings can cause exposure of a user's ALIM session token when the user attempts to download files. This is fixed in Assetwise ALIM Web 23.00.04.04 and Assetwise Information Integrity Server 23.00.02.03.
Configurations

No configuration.

History

No history.

Information

Published : 2024-02-26 16:28

Updated : 2024-11-21 09:04


NVD link : CVE-2024-27455

Mitre link : CVE-2024-27455

CVE.ORG link : CVE-2024-27455


JSON object : View

Products Affected

No product.

CWE
CWE-488

Exposure of Data Element to Wrong Session

CWE-613

Insufficient Session Expiration