CyberRota Analysis
AI analysis pending.
CVE
CVE-2023-39422
Severity
MEDIUM
CVSS
6.5
EPSS
0.36%
Java
Original NVD Description
The /irmdata/api/ endpoints exposed by the IRM Next Generation booking engine authenticates requests using HMAC tokens. These tokens are however exposed in a JavaScript file loaded on the client side, thus rendering this extra safety mechanism useless.
Related CVEs
Other vulnerabilities affecting the same vendor(s)