모든 권고 / BE-2024-0001

BE-2024-0001

BE-2024-0001: ALIM Web Token Exposure

Bentley ID: BE-2024-0001
CVE ID: CVE-2024-27455
Severity: 9.3
CVSS v3.1: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Publication date: 2024-02-19
Revision date: 2024-02-19

Summary
The ALIM Web application may be affected by an issue where certain configuration settings can cause exposure of users ALIM session token when users attempt to download files.

Details
The exposed token may be used in a manner that allows users access to files within ALIM which they do not have permissions to.

영향을 받는 버전

애플리케이션 영향을 받는 버전 완화된 버전
Assetwise ALIM Web >=23.00.04.04
Assetwise Information Integrity Server >=23.00.02.03

 

Recommended Mitigations
Upgrade to latest versions of ALIM Web (23.00.02.03 or later) and Assetwise Information Integrity Server (23.00.04.04 or later). Existing installs hosted by Bentley have already been mitigated. Where upgrade isn’t possible please reach out to Bentley Support for secure configuration instructions.

승인

개정 이력

일자 설명
2024-02-19 1차 권고 버전
2024-03-08 Amend to ALIM Web Version affected
2024-03-25 Amend to versions affected

인프라 납품 및 성능 우수성 축하

2024 Year in Infrastructure & Going Digital Awards

인프라 분야에서 가장 권위 있는 어워드에 프로젝트를 출품하세요! 연장된 참가 마감일은 4월 29일입니다.