9.8

CVE-2023-4501

Authentication bypass in OpenText (Micro Focus) Enterprise Server

User authentication with username and password credentials is ineffective in OpenText (Micro Focus) Visual COBOL, COBOL Server, Enterprise Developer, and Enterprise Server (including product variants such as Enterprise Test Server), versions 7.0 patch updates 19 and 20, 8.0 patch updates 8 and 9, and 9.0 patch update 1, when LDAP-based authentication is used with certain configurations. When the vulnerability is active, authentication succeeds with any valid username, regardless of whether the password is correct; it may also succeed with an invalid username (and any password). This allows an attacker with access to the product to impersonate any user.

Mitigations: The issue is corrected in the upcoming patch update for each affected product. Product overlays and workaround instructions are available through OpenText Support. The vulnerable configurations are believed to be uncommon.

Administrators can test for the vulnerability in their installations by attempting to sign on to a Visual COBOL or Enterprise Server component such as ESCWA using a valid username and incorrect password.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microfocus ≫ Cobol Server Version 7.0 Update patch_update_19
Microfocus ≫ Cobol Server Version 7.0 Update patch_update_20
Microfocus ≫ Cobol Server Version 8.0 Update patch_update_8
Microfocus ≫ Cobol Server Version 8.0 Update patch_update_9
Microfocus ≫ Cobol Server Version 9.0 Update patch_update_1
Microfocus ≫ Enterprise Developer Version 7.0 Update patch_update_19
Microfocus ≫ Enterprise Developer Version 7.0 Update patch_update_20
Microfocus ≫ Enterprise Developer Version 8.0 Update patch_update_8
Microfocus ≫ Enterprise Developer Version 8.0 Update patch_update_9
Microfocus ≫ Enterprise Developer Version 9.0 Update patch_update_1
Microfocus ≫ Enterprise Server Version 7.0 Update patch_update_19
Microfocus ≫ Enterprise Server Version 7.0 Update patch_update_20
Microfocus ≫ Enterprise Server Version 8.0 Update patch_update_8
Microfocus ≫ Enterprise Server Version 8.0 Update patch_update_9
Microfocus ≫ Enterprise Server Version 9.0 Update patch_update_1
Microfocus ≫ Enterprise Test Server Version 7.0 Update patch_update_19
Microfocus ≫ Enterprise Test Server Version 7.0 Update patch_update_20
Microfocus ≫ Enterprise Test Server Version 8.0 Update patch_update_8
Microfocus ≫ Enterprise Test Server Version 8.0 Update patch_update_9
Microfocus ≫ Enterprise Test Server Version 9.0 Update patch_update_1
Microfocus ≫ Visual Cobol Version 7.0 Update patch_update_19
Microfocus ≫ Visual Cobol Version 7.0 Update patch_update_20
Microfocus ≫ Visual Cobol Version 8.0 Update patch_update_8
Microfocus ≫ Visual Cobol Version 8.0 Update patch_update_9
Microfocus ≫ Visual Cobol Version 9.0 Update patch_update_1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.62% 0.45
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
OpenText 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-253 Incorrect Check of Function Return Value

The product incorrectly checks a return value from a function, which prevents it from detecting errors or exceptional conditions.

CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

CWE-305 Authentication Bypass by Primary Weakness

The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.

CWE-358 Improperly Implemented Security Check for Standard

The product does not implement or incorrectly implements one or more security-relevant checks as specified by the design of a standardized algorithm, protocol, or technique.

https://portal.microfocus.com/s/article/KM000021287
Vendor Advisory