Show plain JSON{"configurations": [{"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:microfocus:netiq_advanced_authentication:*:*:*:*:*:*:*:*", "matchCriteriaId": "7D8BAEC8-626A-4520-A89F-DB40CC774D87", "versionEndExcluding": "6.3", "vulnerable": true}, {"criteria": "cpe:2.3:a:microfocus:netiq_advanced_authentication:6.3:-:*:*:*:*:*:*", "matchCriteriaId": "689649F7-75D8-4D13-9A71-50C2908EACA5", "vulnerable": true}, {"criteria": "cpe:2.3:a:microfocus:netiq_advanced_authentication:6.3:sp1:*:*:*:*:*:*", "matchCriteriaId": "A0F82417-D88A-40C5-AD90-7AB826E29C2D", "vulnerable": true}, {"criteria": "cpe:2.3:a:microfocus:netiq_advanced_authentication:6.3:sp2:*:*:*:*:*:*", "matchCriteriaId": "0DD98BB8-7A85-41D6-B1CB-7849D61F085A", "vulnerable": true}, {"criteria": "cpe:2.3:a:microfocus:netiq_advanced_authentication:6.3:sp3:*:*:*:*:*:*", "matchCriteriaId": "729C4860-8CAC-4D4B-8C68-00B1E84E700A", "vulnerable": true}, {"criteria": "cpe:2.3:a:microfocus:netiq_advanced_authentication:6.3:sp4:*:*:*:*:*:*", "matchCriteriaId": "FEFFEB38-B4CA-48ED-9149-073334346CA3", "vulnerable": true}, {"criteria": "cpe:2.3:a:microfocus:netiq_advanced_authentication:6.3:sp4_patch1:*:*:*:*:*:*", "matchCriteriaId": "B14AC9B7-9339-44BA-BF1B-1876DAFBCA14", "vulnerable": true}, {"criteria": "cpe:2.3:a:microfocus:netiq_advanced_authentication:6.3:sp5:*:*:*:*:*:*", "matchCriteriaId": "4A5CE16C-376A-40C1-83E9-2424AAAB668D", "vulnerable": true}, {"criteria": "cpe:2.3:a:microfocus:netiq_advanced_authentication:6.3:sp5_patch1:*:*:*:*:*:*", "matchCriteriaId": "B693A40C-E75F-4937-9500-7068947120A6", "vulnerable": true}, {"criteria": "cpe:2.3:a:microfocus:netiq_advanced_authentication:6.3:sp5_patch2:*:*:*:*:*:*", "matchCriteriaId": "5A6F0324-EF27-4C0E-B737-5F7998A1D555", "vulnerable": true}, {"criteria": "cpe:2.3:a:microfocus:netiq_advanced_authentication:6.3:sp6:*:*:*:*:*:*", "matchCriteriaId": "3396CE81-7FB7-4354-B8C8-5206222F2D98", "vulnerable": true}, {"criteria": "cpe:2.3:a:microfocus:netiq_advanced_authentication:6.3:sp6_patch1:*:*:*:*:*:*", "matchCriteriaId": "7A25944E-674C-4D84-9F3E-F357DB784153", "vulnerable": true}, {"criteria": "cpe:2.3:a:microfocus:netiq_advanced_authentication:6.3:sp7:*:*:*:*:*:*", "matchCriteriaId": "D0BEF722-A582-400C-8696-0CA0A5ABCA46", "vulnerable": true}, {"criteria": "cpe:2.3:a:microfocus:netiq_advanced_authentication:6.4:-:*:*:*:*:*:*", "matchCriteriaId": "BB6165FC-DC61-4354-9769-5BE769BB5313", "vulnerable": true}, {"criteria": "cpe:2.3:a:microfocus:netiq_advanced_authentication:6.4:sp1:*:*:*:*:*:*", "matchCriteriaId": "2B35521A-8FD6-49D2-9BAD-CC2937C68F3C", "vulnerable": true}], "negate": false, "operator": "OR"}]}], "cveTags": [], "descriptions": [{"lang": "en", "value": "Broken access control in Advanced Authentication versions prior to 6.4.1.1 and 6.3.7.2"}], "id": "CVE-2023-24468", "lastModified": "2025-02-27T15:15:36.287", "metrics": {"cvssMetricV31": [{"cvssData": {"attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 9.8, "baseSeverity": "CRITICAL", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.1"}, "exploitabilityScore": 3.9, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary"}]}, "published": "2023-03-15T23:15:09.563", "references": [{"source": "security@opentext.com", "tags": ["Release Notes"], "url": "https://www.netiq.com/documentation/advanced-authentication-63/advanced-authentication-releasenotes-6372/data/advanced-authentication-releasenotes-6372.html"}, {"source": "security@opentext.com", "tags": ["Release Notes"], "url": "https://www.netiq.com/documentation/advanced-authentication-64/advanced-authentication-releasenotes-6411/data/advanced-authentication-releasenotes-6411.html"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Release Notes"], "url": "https://www.netiq.com/documentation/advanced-authentication-63/advanced-authentication-releasenotes-6372/data/advanced-authentication-releasenotes-6372.html"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Release Notes"], "url": "https://www.netiq.com/documentation/advanced-authentication-64/advanced-authentication-releasenotes-6411/data/advanced-authentication-releasenotes-6411.html"}], "sourceIdentifier": "security@opentext.com", "vulnStatus": "Modified", "weaknesses": [{"description": [{"lang": "en", "value": "NVD-CWE-Other"}], "source": "nvd@nist.gov", "type": "Primary"}, {"description": [{"lang": "en", "value": "CWE-284"}], "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary"}]}