Siemens Opcenter QL Home
cpe:2.3:a:siemens:opcenter_quality:*:*:*:*:*:*:*
- >= V13.2, < V2506
A vulnerability exists in Siemens Opcenter Quality SmartClient modules, specifically in Opcenter QL Home (SC), SOA Audit, and SOA Cockpit, all versions prior to V2506. The issue arises because the application fails to enforce mandatory server-side authorization for certain functionalities. This flaw could enable an authenticated attacker to gain complete access to the application.
Exploitation of this vulnerability could allow an authenticated attacker to bypass authorization controls and gain full access to the application, potentially leading to unauthorized actions or data exposure.
Users are advised to update to the latest version of Opcenter Quality. Specific workarounds include removing tools that allow SOAP service calls outside of SmartClient, following the product's security hardening guidelines, and operating SmartClient within a secure network environment.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.