Akamai SIA ThreatAvert Applications Portal Broken Access Control Vulnerability
Vulnerability
A broken access control vulnerability has been identified in Akamai SIA ThreatAvert, specifically in the Applications Portal. This issue is present in the SPS (Security and Personalization Services) version prior to the latest 19.2.0 patch, as well as in Apps Portal versions prior to 19.2.0.3 or 19.2.0.20240814. The vulnerability allows authenticated standard users to bypass authorization controls on the ThreatAvert Policy page. By directly navigating to the policy URI, these users can disable policy enforcement, potentially impacting the application's threat management capabilities.
Impact
Exploitation of this vulnerability allows standard users to access administrative functions on the ThreatAvert Policy page, where they can disable or enable policy enforcement. Such changes are reflected in ThreatAvert block reporting, creating the risk of unauthorized modifications to threat management processes.
Reproduction
To reproduce this vulnerability, an authenticated standard user can access the ThreatAvert Policy page by directly entering the URL for the policy management section. Once on the page, the user can disable or enable various policy enforcement options using the available API endpoints.
Remediation
Users are advised to update to the latest Akamai SIA ThreatAvert patch version 19.2.0.3 or 19.2.0.20240814. For those unable to update immediately, it is recommended to remove ThreatAvert standard user role assignments and rely on Admin users for access to ThreatAvert reports until an upgrade can be performed.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
