When a service is configured to allow only a specific set of roles, but its parent folder is configured to allow public access, any user aware of the service's REST endpoint can bypass security and access the service as if it was publicly accessible.
上次发布: August 25, 2014No Product Found
漏洞 ID 编号
NIM075654
已提交
November 22, 2011
上次修改时间
June 5, 2024
适用范围
No Product Found
找到的版本
10.1
修正版本
10.1
状态
Fixed
此漏洞已得到修复。 有关详细信息,请参阅“版本修复”和“其他信息”(如果适用)。
解决办法
Instead of configuring security for the service, apply the security settings to the parent folder containing the service.