RULE(RULE ID:338315)

Rule General Information
Release Date: 2024-08-13
Rule Name: Glodon OA GetSSOStamp.asmx Authentication Bypass Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Glodon OA is a comprehensive office automation solution , aimed at improving work efficiency and collaboration capabilities within organizations. It provides a series of functions and tools to help enterprises manage and process daily office tasks, processes, and documents, and connects various business systems through the "collaboration+" capability to achieve single sign on, proxy aggregation, function aggregation, as well as data integration and business applications. There is an authentication bypass vulnerability in the GetSSOStamp. asmx of Glodon OA, which allows unauthorized attackers to log in to the system as any user.
Impact: An unauthorized remote attacker can bypass authentication and gain access to the application with specially crafted requests.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.