7.4
CVE-2023-6400
- EPSS 0.09%
- Veröffentlicht 27.03.2024 13:15:46
- Zuletzt bearbeitet 15.04.2026 00:35:42
- Quelle security@opentext.com
- CVE-Watchlists
- Unerledigt
Incorrect user authorization vulnerability on OpenText ZENworks Configuration Management (ZCM) product.
Incorrect Authorization vulnerability in OpenText™ ZENworks Configuration Management (ZCM) allows Unauthorized Use of Device Resources.This issue affects ZENworks Configuration Management (ZCM) versions: 2020 update 3, 23.3, and 23.4.
Daten sind bereitgestellt durch das CVE Programm von Authorized Data Publishers (ADP) (Unstrukturiert)
Herstellermicrofocus
≫
Produkt
zenworks_configuration_management
Default Statusunknown
Version
2020_update3
Status
affected
Version
23.3
Status
affected
Version
23.4
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.09% | 0.27 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@opentext.com | 7.4 | 0.7 | 6 |
CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
|
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.