Use of Hard-coded Credentials in multiple /irmdata/api/ endpoints
Vulnerability Description
The /irmdata/api/ endpoints exposed by the IRM Next Generation booking engine authenticates requests using HMAC tokens. These tokens are however exposed in a JavaScript file loaded on the client side, thus rendering this extra safety mechanism useless.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-39422
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Bitdefender Cyber-Threat Intelligence Lab
More from Resort Data Processing, Inc.
View All →Affected Vendor
Resort Data Processing, Inc.
View all reports →