MoveSortedContentAction in C1 Financial Services Contelligent 9.1.4 does not check "the additional environment security configuration," which allows remote attackers with write permissions to reorder components.
References
Configurations
Information
Published : 2007-03-03 20:19
Updated : 2017-07-29 01:30
NVD link : CVE-2007-1249
Mitre link : CVE-2007-1249
JSON object : View
Products Affected
contelligent
- c1_financial_services
CWE
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
