CyberRota Analysis
AI-GeneratedOpcenter X versions prior to V2604 are vulnerable due to improper validation of the algorithm in the JSON Web Token (JWT) header, allowing unauthenticated remote attackers to forge JWTs. This critical vulnerability enables attackers to bypass authentication, impersonate any user, including administrators, and gain full unauthorized access to the application. Organizations using affected versions should prioritize immediate patching to mitigate potential exploitation.
Original NVD Description
A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header. This could allow an unauthenticated remote attacker to forge arbitrary JWT, bypass authentication mechanisms and impersonate any user including administrative accounts, potentially gaining full unauthorized access to the application.