CVE-2024-12235 | Shenzhen Dashi Tongzhou Information Technology AgileBPM up to 1.0.0 AuthorizationTokenCheckFilter.java doFilter access control
A vulnerability categorized as critical has been discovered in Shenzhen Dashi Tongzhou Information Technology AgileBPM up to 1.0.0. Affected by this issue is the function doFilter of the file \agile-bpm-basic-master\ab-auth\ab-auth-spring-security-oauth2\src\main\java\com\dstz\auth\filter\AuthorizationTokenCheckFilter.java. The manipulation results in improper access controls.
This vulnerability is known as CVE-2024-12235. It is possible to launch the attack remotely. Furthermore, an exploit is available.