Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in AlertEnterprise Guardian 4.1.14.2.2.1. One can bypass manager approval via isAddedByApprover in a Request%20Building%20Access requestSubmit API call. The vendor has stated that the system is protected by updating to a version equal to or greater than one of the following build numbers: 4.1.12.2.1.19, 4.1.12.5.2.36, 4.1.13.0.60, 4.1.13.2.0.3.39, 4.1.13.2.0.3.41, 4.1.13.2.42, 4.1.13.2.25.44, 4.1.14.0.13, 4.1.14.0.43, 4.1.14.0.48, and 4.1.14.1.5.32.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Alert Enterprise Guardian 安全漏洞
Vulnerability Description
Alert Enterprise Guardian是美国Alert Enterprise开源的一款实物身份与访问管理系统。 AlertEnterprise Guardian 4.1.14.2.2.1版本存在安全漏洞,该漏洞源于通过Request%20Building%20Access requestSubmit API调用中的isAddedByApprover绕过经理审批。
CVSS Information
N/A
Vulnerability Type
N/A