4

CVE-2025-6943

Secret Server version 11.7 and earlier is vulnerable to a SQL report creation vulnerability that allows an administrator to gain access to restricted tables.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DelineaSecret Server SwEditionon-premises Version < 11.7.000060
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.14% 0.034
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4 0.6 3.4
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L
1443cd92-d354-46d2-9290-d812316ca43a 3.8 0.3 3.4
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:L
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

https://docs.delinea.com/online-help/secret-server/release-notes/ss-rn-11-7-000060.htm
Release Notes
https://docs.delinea.com/online-help/secret-server/release-notes/ss-rn-11-7-000061.htm
Release Notes
https://docs.delinea.com/online-help/secret-server-changelog/secret-server-change-log.htm?cshid=secret-server-changelog#Friday,_November_22,_2024
Release Notes
https://trust.delinea.com
Vendor Advisory