Description
In RSA NetWitness (NW) Platform before 12.5.1, even when an administrator revokes the access of a specific user with an active session, an internal threat actor could impersonate the revoked user and gain unauthorized access to sensitive data.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Thu, 21 Nov 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rsa
Rsa netwitness Platform |
|
| Weaknesses | CWE-276 | |
| CPEs | cpe:2.3:a:rsa:netwitness_platform:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Rsa
Rsa netwitness Platform |
|
| Metrics |
cvssV3_1
|
Mon, 18 Nov 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In RSA NetWitness (NW) Platform before 12.5.1, even when an administrator revokes the access of a specific user with an active session, an internal threat actor could impersonate the revoked user and gain unauthorized access to sensitive data. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-11-21T16:58:23.034Z
Reserved: 2024-03-01T00:00:00.000Z
Link: CVE-2024-28058
Updated: 2024-11-21T16:58:17.440Z
Status : Deferred
Published: 2024-11-18T15:15:05.843
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-28058
No data.
OpenCVE Enrichment
No data.
Weaknesses