Ericsson Network Manager (ENM) before 21.2 has incorrect access-control behavior (that only affects the level of access available to persons who were already granted a highly privileged role). Users in the same AMOS authorization group can retrieve managed-network data that was not set to be accessible to the entire group (i.e., was only set to be accessible to a subset of that group).
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2022-03-08T22:51:21
Updated: 2024-08-03T21:47:32.592Z
Reserved: 2021-03-16T00:00:00
Link: CVE-2021-28488
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-03-10T17:42:08.193
Modified: 2024-11-21T05:59:46.053
Link: CVE-2021-28488
Redhat
No data.