CVE-2025-49651
BaseFortify
Publication date: 2025-06-09
Last updated on: 2025-06-12
Assigner: HiddenLayer
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-862 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in Lablup's BackendAI is a Missing Authorization flaw that allows attackers to take over all active sessions. By exploiting this, attackers can access, steal, or alter any data accessible within those sessions. Essentially, unauthorized users can hijack sessions and perform actions as if they were the legitimate users.
How can this vulnerability impact me? :
The impact of this vulnerability is severe. Attackers can take over active sessions, which means they can access sensitive data, steal information, and modify data within those sessions. This can lead to data breaches, loss of data integrity, and disruption of services. The CVSS score of 8.1 indicates high severity with high impact on confidentiality, integrity, and availability.