Invensys Wonderware Information Server 4.0 SP1 and 4.5 does not properly implement client controls, which allows remote attackers to bypass intended access restrictions via unspecified vectors.Referenceshttp://www.securitytracker.com/id?1026886http://secunia.com/advisories/48603http://osvdb.org/80890http://www.securityfocus.com/bid/52851http://www.us-cert.gov/control_systems/pdf/ICSA-12-062-01.pdfhttp://www.securitytracker.com/id?1026887