PT-2026-84285 · Cleo · Cleo Harmony
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Cleo Harmony versions prior to 5.8.1.11
Description
An issue exists in the SAML Authentication component where manipulation of the
Email argument within the LocalUserUtil.getNativeUserByAssertions() function allows for improper authentication. This flaw can be exploited remotely.Recommendations
Update to version 5.8.1.11.
Upgrade the SAML Authentication component.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cleo Harmony