Persistent Systems Radia Client Automation does not...
High severity
Unreviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Apr 12, 2025
Description
Published by the National Vulnerability Database
Feb 16, 2015
Published to the GitHub Advisory Database
May 17, 2022
Last updated
Apr 12, 2025
Persistent Systems Radia Client Automation does not properly restrict access to certain request, which allows remote attackers to (1) enumerate user accounts via a getUsers request, (2) assign a role to a user account via an addAssigneesToRole request, (3) remove a role from a user account via a removeAssigneesFromRole request, or (4) have other unspecified impact.
References