Tata Consultancy Services Cognix Recon Client Missing Authentication and Authorization Vulnerability
Vulnerability
A vulnerability exists in the web API of Tata Consultancy Services (TCS) Cognix Recon Client version 3.0, due to missing authentication and authorization. This flaw allows remote attackers to access application functionality without proper restrictions. The affected endpoints include reconciliations, Scheduler, and DynamicReport.
Impact
Exploitation of this vulnerability could lead to unauthorized access to application functionality, bypassing authentication and authorization controls.
Remediation
TCS has implemented mandatory authentication requirements and improved authorization validation across the affected API endpoints. This vulnerability has been verified as remediated in the current version of the product.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
