Omnis Studio 10.22.00 has incorrect access control. It advertises a feature for making Omnis libraries "always private" - this is supposed to be an irreversible operation. However, due to implementation issues, "always private" Omnis libraries can be opened by the Omnis Studio browser by bypassing specific checks. This violates the expected behavior of an "irreversible operation".
Metrics
Affected Vendors & Products
References
History
Thu, 24 Oct 2024 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-276 | |
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2023-07-20T00:00:00
Updated: 2024-10-24T20:28:58.255Z
Reserved: 2023-07-14T00:00:00
Link: CVE-2023-38335
Vulnrichment
Updated: 2024-08-02T17:39:12.753Z
NVD
Status : Modified
Published: 2023-07-20T18:15:12.227
Modified: 2024-11-21T08:13:21.500
Link: CVE-2023-38335
Redhat
No data.