Database/Firmware, BMC & network fabric

Sunbird DCIM dcTrack v9.1.2 - ticket location RBAC: Incorrect access control lets an attacker create or update tickets
Impact
Incorrect access control lets an attacker create or update tickets against locations they should not have access to, bypassing the RBAC check. In a multi-tenant colo or a shared cage environment, that is a tenant-boundary problem inside the facility workflow system - work orders touching another customer's rack.
Who can reach it
Any authenticated dcTrack user.
What to do
Upgrade past 9.1.2. If you run dcTrack with per-customer location scoping as a tenant-isolation control, treat that control as having been ineffective for the affected period and review the ticket history.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.