desknet's NEO Improper Protection of Alternate Path Vulnerability in AppSuite

Vulnerability

A vulnerability allowing attackers to create malicious AppSuite applications has been identified in desknet's NEO versions 4.0R1.0 through 9.0R2.0. This issue arises from improper protection of alternate paths, which could be exploited by remote authenticated attackers.

Impact

Exploitation of this vulnerability could lead to the creation of unauthorized AppSuite applications by a remote authenticated attacker.

Remediation

Users are advised to update desknet's NEO to version 9.5 R1.0 or later. For those using the PostgreSQL or SQL Server versions, download and install the update module. Oracle version users should contact NEOJAPAN for guidance.

Added: Oct 16, 2025, 10:19 AM
Updated: Oct 16, 2025, 3:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
1.7
exploitability
4.9
remediation
7.7
relevance
0.7
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.