CyberRota Analysis
AI-GeneratedThe vulnerability in Cash Collect's Sage AR Automation API allows authenticated users to bypass tenant-level authorization, enabling them to access administrative resources of other tenants by manipulating tenant identifiers. This critical flaw poses a significant risk of unauthorized data exposure and potential administrative control over affected systems. Organizations utilizing this API should prioritize immediate remediation to safeguard sensitive information and maintain tenant isolation.
Original NVD Description
Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Insufficient tenant-level authorization checks allow authenticated users to access administrative resources belonging to other tenants by specifying a valid non predictable tenant identifier.