Summary The UMA 2.0 Protection API endpoint for permission tickets fails to enforce the uma_protection role check. This allows any authenticated user with a token issued for a resource server client to enumerate all permission tickets in the system. Requirements to exploit: An attacker must possess a valid, authenticated user token for a resource server client that lacks the uma_protection role.