CVE-2017-9421

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
24/05/2018
Last modified:
27/06/2018

Description

Authentication Bypass vulnerability in Accellion kiteworks before 2017.01.00 allows remote attackers to execute certain API calls on behalf of a web user using a gathered token via a POST request to /oauth/token.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:accellion:kiteworks:*:*:*:*:*:*:*:* 2017.01.00 (excluding)