Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an unprivileged attacker to modify the permissions held by each of the application's users, including the user himself by sending a POST request to /PC/Options.aspx?Command=2&Page=-1.
History

Mon, 09 Jun 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 09 Jun 2025 12:45:00 +0000

Type Values Removed Values Added
Description Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an unprivileged attacker to modify the permissions held by each of the application's users, including the user himself by sending a POST request to /PC/Options.aspx?Command=2&Page=-1.
Title Incorrect Authorization vulnerability in TCMAN GIM
Weaknesses CWE-863
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published: 2025-06-09T12:26:11.761Z

Updated: 2025-06-09T13:02:46.021Z

Reserved: 2025-04-16T08:38:14.998Z

Link: CVE-2025-40669

cve-icon Vulnrichment

Updated: 2025-06-09T13:02:43.600Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-09T13:15:22.803

Modified: 2025-06-12T16:06:47.857

Link: CVE-2025-40669

cve-icon Redhat

No data.