Metrics
Affected Vendors & Products
Mon, 24 Feb 2025 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
cvssV3_1
|
Wed, 29 Jan 2025 12:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Wed, 29 Jan 2025 11:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Mon, 27 Jan 2025 11:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | API Security bypass through header manipulation | In Xerox Workplace Suite, an API restricted to specific hosts can be bypassed by manipulating the Host header. If the server improperly validates or trusts the Host header without verifying the actual destination, an attacker can forge a value to gain unauthorized access. This exploit targets improper host validation, potentially exposing sensitive API endpoints. |
Thu, 23 Jan 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 23 Jan 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | API Security bypass through header manipulation | |
Title | API Security bypass through header manipulation | |
Weaknesses | CWE-287 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Xerox
Published: 2025-01-23T17:03:33.187Z
Updated: 2025-02-24T17:09:59.029Z
Reserved: 2024-12-13T14:30:30.206Z
Link: CVE-2024-55925

Updated: 2025-01-23T18:57:07.683Z

Status : Awaiting Analysis
Published: 2025-01-23T17:15:15.380
Modified: 2025-02-24T18:15:17.823
Link: CVE-2024-55925

No data.