漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
LogRhythm Platform Manager (PM) 7.4.9 has Incorrect Access Control. Users within LogRhythm can be delegated different roles and privileges, intended to limit what data and services they can interact with. However, no access control is enforced for WebSocket-based communication to the PM application server, which will forward requests to any configured back-end server, regardless of whether the user's access rights should permit this. As a result, even the most low-privileged user can interact with any back-end component that has a LogRhythm agent installed.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Logrhythm Platform Manager 安全漏洞
Vulnerability Description
Logrhythm Platform Manager是美国Logrhythm公司的一个Logrhyth应用的组件。该组件负责集中管理告警、通知和案例和安全事件管理。支撑实时仪表板,SmartResponse操作和报告。 LogRhythm Platform Manager (PM) 7.4.9 存在安全漏洞,该漏洞源于访问控制不正确。特权最低的用户也可以与安装了LogRhythm代理的任何后端组件进行交互。
CVSS Information
N/A
Vulnerability Type
N/A