5
CVSSv2

CVE-2020-28861

Published: 14/12/2020 Updated: 15/12/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

OpenAsset Digital Asset Management (DAM) 12.0.19 and previous versions failed to implement access controls on /Stream/ProjectsCSV endpoint, allowing unauthenticated malicious users to gain access to potentially sensitive project information stored by the application.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openasset digital asset management

Exploits

OpenAsset Digital Asset Management was found to provide several endpoints which allowed for unauthenticated data retrieval in a CSV format Vulnerable versions include 12019 (Cloud) and 1121 (On-premise) ...