High severity7.1NVD Advisory· Published Nov 4, 2024· Updated Jun 17, 2026
CVE-2024-45164
CVE-2024-45164
Description
Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch and Apps Portal before 19.2.0.3 or 19.2.0.20240814, has incorrect authorization controls for the Admin functionality on the ThreatAvert Policy page. An authenticated user can navigate directly to the /#app/intelligence/threatAvertPolicies URI and disable policy enforcement.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- cpe:2.3:a:akamai:secure_internet_access_enterprise_threatavert:19.2.0.2:*:*:*:*:*:*:*
- Range: <19.2.0
- Range: <19.2.0.3 or <19.2.0.20240814
Patches
Vulnerability mechanics
References
2- notes.netbytesec.com/2024/11/cve-2024-45164-broken-access-control.htmlnvdExploitMitigationThird Party Advisory
- www.akamai.com/global-services/support/vulnerability-reportingnvdProduct
News mentions
0No linked articles in our index yet.