Description
In Akamai EAA (Enterprise Application Access) Client before 2.3.1, 2.4.x before 2.4.1, and 2.5.x before 2.5.3, an unquoted path may allow an attacker to hijack the flow of execution.
References
https://akamai.com/blog/news/eaa-client-escalation-of-privilege-vulnerability
ExploitVendor Advisory
https://www.akamai.com/products/enterprise-application-access
ProductVendor Advisory
https://akamai.com/blog/news/eaa-client-escalation-of-privilege-vulnerability
ExploitVendor Advisory
https://www.akamai.com/products/enterprise-application-access
ProductVendor Advisory
CVSS impact metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.8 · High
Information
Source identifier
Vulnerability status
Modified
Published
2021-10-04T15:15:08.467Z
4 years agoLast modified
2024-11-21T05:24:33.870Z
1 year ago