CISA

Johnson Controls Simplex Incident Manager

From Cybersecurity and Infrastructure Security Agency ↗

Successful exploitation of this vulnerability could allow a local attacker with low privileges to extract user credentials (passwords and authentication tokens) from system memory, potentially leading to unauthorized access to the application and connected systems.

The following versions of Johnson Controls Simplex Incident Manager are affected:

Simplex Incident Manager