445
VMScore

CVE-2020-28856

Published: 14/12/2020 Updated: 15/12/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

OpenAsset Digital Asset Management (DAM) up to and including 12.0.19 does not correctly determine the HTTP request's originating IP address, allowing malicious users to spoof it using X-Forwarded-For in the header, by supplying localhost address such as 127.0.0.1, effectively bypassing all IP address based access controls.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openasset digital asset management

Exploits

The OpenAsset Digital Asset Management web application allowed for spoofing of IP addresses by using X-Forwarded-For header By default, the web application would allow all traffic in for 127001, in order to prevent users from accidentally blocking themselves Vulnerable versions include 12019 (Cloud) and 1121 (On-premise) ...