Basic Analysis and Security Engine (BASE) contains a flaw that may allow a malicious user to gain full privileges without authentication. The issue is triggered when using HTTP client that does not follow redirects. It is possible that the flaw may allow unauthorized administrative access resulting in a loss of integrity.
Classification
Location:
Remote / Network Access
Attack Type:
Authentication Management
Impact:
Loss of Integrity
Exploit:
Exploit Public
Disclosure:
Vendor Verified
OSVDB:
Web Related
Solution
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.