Headline
CVE-2021-40354
A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.8), Teamcenter V13.0 (All versions < V13.0.0.7), Teamcenter V13.1 (All versions < V13.1.0.5), Teamcenter V13.2 (All versions < 13.2.0.2). The “surrogate” functionality on the user profile of the application does not perform sufficient access control that could lead to an account takeover. Any profile on the application can perform this attack and access any other user assigned tasks via the "inbox/surrogate tasks".
%PDF-1.5 %���� 1 0 obj << /D [2 0 R /XYZ 70.866 771.024 null] >> endobj 3 0 obj << /D [2 0 R /XYZ 70.866 646.963 null] >> endobj 4 0 obj << /D [2 0 R /XYZ 70.866 598.838 null] >> endobj 5 0 obj << /D [2 0 R /XYZ 70.866 370.413 null] >> endobj 6 0 obj << /D [2 0 R /XYZ 70.866 281.442 null] >> endobj 7 0 obj << /D [8 0 R /XYZ 85.039 337.375 null] >> endobj 9 0 obj << /D [10 0 R /XYZ 70.866 713.397 null] >> endobj 11 0 obj << /S /GoTo /D [2 0 R /Fit] >> endobj 2 0 obj << /Contents 12 0 R /Type /Page /Resources 13 0 R /Parent 14 0 R /Annots [15 0 R 16 0 R 17 0 R 18 0 R 19 0 R 20 0 R 21 0 R] /MediaBox [0 0 595.276 841.89] >> endobj 15 0 obj << /A << /S /URI /Type /Action /URI (https://support.sw.siemens.com/) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [303.117 497.876 446.757 510.783] >> endobj 16 0 obj << /A << /S /URI /Type /Action /URI (https://support.sw.siemens.com/) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [303.117 461.478 446.757 474.385] >> endobj 17 0 obj << /A << /S /URI /Type /Action /URI (https://support.sw.siemens.com/) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [303.117 425.08 446.757 437.986] >> endobj 18 0 obj << /A << /S /URI /Type /Action /URI (https://support.sw.siemens.com/) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [303.117 388.682 446.757 401.588] >> endobj 19 0 obj << /A << /S /URI /Type /Action /URI (https://www.siemens.com/cert/operational-guidelines-industrial-security) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [164.798 189.37 487.754 200.907] >> endobj 20 0 obj << /A << /S /URI /Type /Action /URI (https://www.siemens.com/industrialsecurity) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [406.699 159.602 525.406 171.019] >> endobj 22 0 obj << /A << /S /URI /Type /Action /URI (https://www.first.org/cvss/) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [131.954 722.78 248.203 734.316] >> endobj 13 0 obj << /ProcSet [/PDF /Text] /Font << /F50 23 0 R /F47 24 0 R >> >> endobj 12 0 obj << /Filter /FlateDecode /Length 2674 >> stream x��Z�s�6�_��R3B|D�^T[鹍�,��I��H��+E�"e_���@Y�(�9s3��C $���.wx/�~>�iz��P�&:d�7��T@�0���DR�M���&M�I^�LE�M2۬C*������iY� |7�m�������|3��Ǔ�=�>��l<=��C�G��Dq�͖g_~�9<��ב�h�\zBr"��̻9��Y���� �(��! "�E3D+�%i�#�’Z(�� � #����PGJ���@TJBY��% m�ޥ��Q/��n�i*��W��JWYr�=������K��>�!��CB�����}$��n��i�&˓u�-��*M�CI8 ���I8$R� P[�t�$��_Pٔ$�[g C��8�`tڇ�RDs��8�6�� �x9K�*Y!����x�dn$�[:7:�tWi�[и���-�K$��F��R���!�D��N���s���YRQzl����7�5�m’~D ɺ��a���?Q���tsc’=���w?�e�poV��J,� u��P֪�s[��t��(��v�,���@K�WW��@�o����A&�Ĉ� 9a`��1(�юE�LS?Eׁ�� ���Y���-����~�$v�����)i��2���i�Z1�h��E��C�%G’.�t�C�~��_�%��R�H�t4�^ i���t��?v��$�����g�`_\^\O���s{��꽽��*C��ʫm(��q���"�ϟ�H�X|�c0�1.-�O�2�}ln��N��jn�7Ʊ�; �1���>�7h��#+vA+�֊%�8w�bw �r=�����}�0M��R ' G�\��H��./��f����P� t�p����|:�h��L�@�Y `�%�r��%i�H��=�?Np�\_ܞOoZ$М��4thе &��S *�g�-�gҌ�g�v�8�"4]�#1!U��������->���<) 5�_Z밑���x��4$�` �E^��FX���W�������4�c�T�.��a�Jk��Ļ�I�k�|9(Ñ䜄�}9���k 2�?���=���� c��-���U����P�{�Bx