CVE-2022-39038
Severity CVSS v4.0:
Pending analysis
Type:
CWE-287
Authentication Issues
Publication date:
10/11/2022
Last modified:
15/11/2022
Description
Agentflow BPM enterprise management system has improper authentication. A remote attacker with general user privilege can change the name of the user account to acquire arbitrary account privilege, and access, manipulate system or disrupt service.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:flowring:agentflow:4.0.0.1183.552:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



