Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch and Apps Portal before 19.2.0.3 or 19.2.0.20240814, has incorrect authorization controls for the Admin functionality on the ThreatAvert Policy page. An authenticated user can navigate directly to the /#app/intelligence/threatAvertPolicies URI and disable policy enforcement.
References
Link | Resource |
---|---|
https://notes.netbytesec.com/2024/11/cve-2024-45164-broken-access-control.html | Exploit Mitigation Third Party Advisory |
https://www.akamai.com/global-services/support/vulnerability-reporting | Product |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2024-11-04 14:15
Updated : 2024-11-06 17:35
NVD link : CVE-2024-45164
Mitre link : CVE-2024-45164
CVE.ORG link : CVE-2024-45164
JSON object : View
Products Affected
akamai
- secure_internet_access_enterprise_threatavert