Executive brief
Industrial Application Software (IAS) Canias ERP, an enterprise resource planning platform used in manufacturing and industrial environments, contains a security flaw in its remote communication interface. An unauthenticated attacker can remotely query the system to obtain a list of all currently active user sessions, including session IDs, usernames, and IP addresses. This information can be used as a stepping stone to hijack active sessions and eventually gain full control over the server.
Technical details
An improper authentication vulnerability (CWE-287) exists in the 'doAction' function of the Java RMI Interface in IAS Canias ERP 8.03. The 'iasGetUserListEvent' handler fails to validate authentication or session state before processing requests. A remote, unauthenticated attacker can craft a malicious RMI request to trigger this event, which returns a list of all active 'iasSessionInfo' objects. This leaked data includes sensitive session identifiers (sessionId), usernames, and client IP addresses. These session IDs can subsequently be used to bypass authentication in other interface methods, forming part of a chain that leads to remote code execution (RCE). As of the advisory date, the vendor has not provided a patch.
Affected products
- Industrial Application Software (IAS) Canias ERP 8.03
Timeline
- 2025-04: other: Vulnerability research began
- 2026-05-09: disclosed: Public disclosure by security researcher
- 2026-05-10: advisory: CVE published to NVD