Executive brief
Universal Software Inc. FlexCity is susceptible to a vulnerability where it fails to limit repeated login attempts. This flaw allows an attacker to overwhelm the system's resources by making excessive authentication requests, potentially leading to a denial of service or system instability. This could disrupt business operations and prevent legitimate users from accessing the platform.
Technical details
The vulnerability is classified as CWE-307 (Improper Restriction of Excessive Authentication Attempts) within the FlexCity application. It occurs because the system does not adequately throttle or block repeated login requests, which leads to excessive resource allocation (denial of service). An attacker with low-level privileges can exploit this over a network without user interaction to impact the availability of the service. The issue affects versions 5.536.0 through 11052026.
Affected products
- Universal Software Inc. FlexCity 5.536.0 through 11052026
Timeline
- 2026-07-21: advisory: Published by NVD and TR-CERT