A formula injection vulnerability exists in Tenable Identity Exposure where an authenticated remote attacker with administrative privileges could manipulate application form fields in order to trick another administrator into executing CSV payloads. - CVE-2024-3232
Metrics
Affected Vendors & Products
Fixes
Solution
Tenable has released Tenable Identity Exposure Version 3.59.4 to address these issues. The installation files can be obtained from the Tenable Downloads Portal: https://www.tenable.com/downloads/identity-exposure
Workaround
No workaround given by the vendor.
References
Link | Providers |
---|---|
https://www.tenable.com/security/tns-2024-04 |
![]() ![]() ![]() |
History
No history.

Status: PUBLISHED
Assigner: tenable
Published:
Updated: 2024-08-01T20:05:08.350Z
Reserved: 2024-04-02T19:00:49.569Z
Link: CVE-2024-3232

Updated: 2024-08-01T20:05:08.350Z

Status : Awaiting Analysis
Published: 2024-07-16T17:15:11.267
Modified: 2024-11-21T09:29:12.230
Link: CVE-2024-3232

No data.

No data.