Security Advisory

CVE-2022-39038

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-11-10 02:20:46
Last updated 2025-05-01 19:06:11
Assigner twcert
State PUBLISHED

Description

Agentflow BPM enterprise management system has improper authentication. A remote attacker with general user privilege can change the name of the user account to acquire arbitrary account privilege, and access, manipulate system or disrupt service.