Altair PBS Professional through 19.1.2 allows Privilege Escalation because an attacker can send a message directly to pbs_mom, which fails to properly authenticate the message. This results in code execution as an arbitrary user.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:a:altair:pbs_professional:*:*:*:*:*:*:*:*"
],
"vendor_product": "altair:pbs_professional",
"extracted_events": [
{
"introduced": "13.0.0"
},
{
"fixed": "13.0.412"
},
{
"introduced": "14.0.0"
},
{
"fixed": "14.2.7"
},
{
"introduced": "18.0.0"
},
{
"fixed": "18.2.5"
},
{
"introduced": "19.1.0"
},
{
"fixed": "19.1.3"
},
{
"introduced": "19.2.0"
},
{
"fixed": "19.2.4"
}
],
"source": "CPE_RANGE"
}
]
}