An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to escalate privileges via a crafted POST request to the grantRolesToUsers, grantRolesToGroups, and grantRolesToOrganization SOAP API component.
| Software | From | Fixed in |
|---|---|---|
| ncr / terminal_handler | 1.5.1 | 1.5.1.x |