7.5
CVE-2020-11846
- EPSS 0.33%
- Veröffentlicht 21.08.2024 14:15:07
- Zuletzt bearbeitet 23.08.2024 17:03:39
- Erkennungen
Improper handling of token allows access to restricted resource in Privileged Access Manager
A vulnerability found in OpenText Privileged Access Manager that issues a token. on successful issuance of the token, a cookie gets set that allows unrestricted access to all the application resources. This issue affects Privileged Access Manager before 3.7.0.1.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microfocus ≫ Netiq Privileged Access Manager Version < 3.7
Microfocus ≫ Netiq Privileged Access Manager Version 3.7 Update -
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.33% | 0.253 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| OpenText | 8.7 | 2.3 | 5.8 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
https://www.netiq.com/documentation/privileged-account-manager-37/npam_3701_releasenotes/data/npam_3701_releasenotes.html