Vulnerability Description
In GFOS Workforce Management 4.8.272.1, the login page of application is prone to authentication bypass, allowing anyone (who knows a user's credentials except the password) to get access to an account. This occurs because of JSESSIONID mismanagement.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gfos | Workforce Management | 4.8.272.1 |
References
- https://cds.thalesgroup.com/en/tcs-cert/CVE-2021-38618
- https://excellium-services.com/cert-xlm-advisory/cve-2021-38618/Third Party Advisory
- https://excellium-services.com/cert-xlm-advisory/cve-2021-38618/Third Party Advisory
FAQ
What is CVE-2021-38618?
CVE-2021-38618 is a vulnerability with a CVSS score of 7.4 (HIGH). In GFOS Workforce Management 4.8.272.1, the login page of application is prone to authentication bypass, allowing anyone (who knows a user's credentials except the password) to get access to an accoun...
How severe is CVE-2021-38618?
CVE-2021-38618 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-38618?
Check the references section above for vendor advisories and patch information. Affected products include: Gfos Workforce Management.