Junglewise Threat Intelligence

CVE-2015-4626: B.A.S C2Box business logic corruption via client-side validation bypass

CVE-2015-4626 · Severity: high · CVSS 7.5 · Published 2017-01-23

Executive brief

B.A.S C2Box, a treasury and cash management platform, contains a flaw in how it validates financial data. An attacker can bypass security checks to input negative values into overdraft fields, potentially allowing them to manipulate financial records or corrupt the system's business logic. This could lead to unauthorized financial adjustments or inaccurate reporting within the organization's treasury operations.

Technical details

The vulnerability is a numeric error (CWE-189) resulting from a reliance on client-side validation for sensitive business logic. Specifically, the application fails to perform server-side checks on overdraft values, allowing a remote attacker to submit negative integers. By bypassing the client-side interface, an attacker can manipulate the integrity of financial transactions or the underlying business logic. This is reachable over the network without authentication. The issue was addressed in version 4.0.0 (r19171).

Affected products

  • B.A.S (TreasuryXpress) C2Box before 4.0.0 (r19171)

Timeline

  • 2015-06-16: disclosed: CVE assigned
  • 2017-01-23: advisory: NVD publication date

References