5.3

CVE-2023-38335

Exploit
Omnis Studio 10.22.00 has incorrect access control. It advertises a feature for making Omnis libraries "always private" - this is supposed to be an irreversible operation. However, due to implementation issues, "always private" Omnis libraries can be opened by the Omnis Studio browser by bypassing specific checks. This violates the expected behavior of an "irreversible operation".
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OmnisStudio Version10.22.00
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.09% 0.61
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-276 Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.

http://seclists.org/fulldisclosure/2023/Jul/43
Not Applicable
http://packetstormsecurity.com/files/173695/Omnis-Studio-10.22.00-Library-Setting-Bypass.html
Third Party Advisory
Exploit
VDB Entry
http://seclists.org/fulldisclosure/2023/Jul/41
Third Party Advisory
Exploit
Mailing List
https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2023-005.txt
Third Party Advisory