CVE-2024-45164 Details
Description
Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch and Apps Portal before 19.2.0.3 or 19.2.0.20240814, has incorrect authorization controls for the Admin functionality on the ThreatAvert Policy page. An authenticated user can navigate directly to the /#app/intelligence/threatAvertPolicies URI and disable policy enforcement.
A broken access control vulnerability has been identified in Akamai SIA ThreatAvert, specifically in the Applications Portal. This issue is present in the SPS (Security and Personalization Services) version prior to the latest 19.2.0 patch, as well as in Apps Portal versions prior to 19.2.0.3 or 19.2.0.20240814. The vulnerability allows authenticated standard users to bypass authorization controls on the ThreatAvert Policy page. By directly navigating to the policy URI, these users can disable policy enforcement, potentially impacting the application's threat management capabilities.
Users are advised to update to the latest Akamai SIA ThreatAvert patch version 19.2.0.3 or 19.2.0.20240814. For those unable to update immediately, it is recommended to remove ThreatAvert standard user role assignments and rely on Admin users for access to ThreatAvert reports until an upgrade can be performed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 6, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://notes.netbytesec.com/2024/11/cve-2024-45164-broken-access-control.html | [email protected] | ExploitMitigationThird Party Advisory |
| https://www.akamai.com/global-services/support/vulnerability-reporting | [email protected] | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
| CWE-732 | Incorrect Permission Assignment for Critical Resource | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| akamai secure internet access enterprise threatavert | 19.2.0.2 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 6, 2024 | CVE Modified | CISA-ADP |
| Nov 6, 2024 | Initial Analysis | [email protected] |
| Nov 4, 2024 | New CVE Received | [email protected] |