[Security advisory for CVE-2021-44526] Authentication bypass vulnerability in SupportCenter Plus versions up to 11017

[Security advisory for CVE-2021-44526] Authentication bypass vulnerability in SupportCenter Plus versions up to 11017

Hi there,

 

This security advisory addresses an authentication bypass vulnerability that affects SupportCenter Plus versions up to 11017.

 

Please note that we are noticing exploits of this vulnerability, and we strongly urge all customers using SupportCenter Plus (all editions) with versions up to 11017 to update to the latest version immediately.

 

Severity: High

 

Impact:

This vulnerability allows an adversary to gain unauthorized access to the application's data through a few application URLs. To do so, an attacker has to manipulate any vulnerable application URL path from the module with a proper character set replacement.

 

What led to the vulnerability?

One of the application filters used for handling state in the list view was not configured properly, and a crafted URL using this filter would enable an authenticated servlet to be accessed without proper authentication. APIs and other URL calls are not affected.

 

Who is affected?

This vulnerability affects SupportCenter Plus customers of all editions using versions up to 11017.

 

How have we fixed it?

We have added additional checks to ensure the filters are properly configured to avoid the authentication bypass vulnerability.

 

How to find out if you are affected

Click the Help link in the top-right corner of the SupportCenter Plus web client, and select About from the drop-down to see your current version. If your current version is 11017 and below, you might be affected.

 

What customers should do

Customers who fit the above criteria can upgrade to the latest version (11018) using the appropriate migration path.

 

Please read the upgrade instructions carefully before beginning the upgrade. For assistance, write to support@supportcenterplus.com or call us toll-free at +1.888.720.9500.

 

Important note: As always, make a copy of the entire SupportCenter Plus installation folder before applying the upgrade, and keep the copy in a separate location. If anything goes wrong during the upgrade, you'll have this copy as a backup, which will keep all your settings intact. If you're using an MS SQL server as a back-end database, back up the SupportCenter Plus database before upgrading. Once the upgrade is successfully completed, remember to delete the backup.

 

We offer our sincerest apologies for any inconvenience this may have caused. If you have any questions or concerns, please reach out to us at support@supportcenterplus.com.


                New to ADManager Plus?

                  New to ADSelfService Plus?