A vulnerability found in OpenText Privileged Access Manager that issues a token. on successful issuance of the token, a cookie gets set that allows unrestricted access to all the application resources. This issue affects Privileged Access Manager before 3.7.0.1.
History

Fri, 23 Aug 2024 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Microfocus
Microfocus netiq Privileged Access Manager
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:microfocus:netiq_privileged_access_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:netiq_privileged_access_manager:3.7:-:*:*:*:*:*:*
Vendors & Products Microfocus
Microfocus netiq Privileged Access Manager

Wed, 21 Aug 2024 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Opentext
Opentext privileged Access Manager
CPEs cpe:2.3:a:opentext:privileged_access_manager:*:*:*:*:*:*:*:*
Vendors & Products Opentext
Opentext privileged Access Manager
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 21 Aug 2024 13:45:00 +0000

Type Values Removed Values Added
Description A vulnerability found in OpenText Privileged Access Manager that issues a token. on successful issuance of the token, a cookie gets set that allows unrestricted access to all the application resources. This issue affects Privileged Access Manager before 3.7.0.1.
Title Improper handling of token allows access to restricted resource in Privileged Access Manager
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: OpenText

Published: 2024-08-21T13:37:11.454Z

Updated: 2024-08-21T14:40:15.436Z

Reserved: 2020-04-16T00:00:00.000Z

Link: CVE-2020-11846

cve-icon Vulnrichment

Updated: 2024-08-21T14:40:03.861Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-21T14:15:07.737

Modified: 2024-08-23T17:03:39.093

Link: CVE-2020-11846

cve-icon Redhat

No data.