There is an insufficient input validation vulnerability in
the Warehouse component of Absolute Secure Access prior to 13.06. Attackers
with system administrator permissions can impair the availability of certain
elements of the Secure Access administrative UI by writing invalid data to the
warehouse over the network. There is no loss of warehouse integrity or
confidentiality, the security scope is unchanged. Loss of availability is high.
the Warehouse component of Absolute Secure Access prior to 13.06. Attackers
with system administrator permissions can impair the availability of certain
elements of the Secure Access administrative UI by writing invalid data to the
warehouse over the network. There is no loss of warehouse integrity or
confidentiality, the security scope is unchanged. Loss of availability is high.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-36603 | There is an insufficient input validation vulnerability in the Warehouse component of Absolute Secure Access prior to 13.06. Attackers with system administrator permissions can impair the availability of certain elements of the Secure Access administrative UI by writing invalid data to the warehouse over the network. There is no loss of warehouse integrity or confidentiality, the security scope is unchanged. Loss of availability is high. |
Fixes
Solution
Upgrade to Absolute Secure Access v13.06 or later.
Workaround
No workaround given by the vendor.
References
History
Wed, 07 Aug 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Absolute
Absolute secure Access |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Absolute
Absolute secure Access |
Status: PUBLISHED
Assigner: Absolute
Published:
Updated: 2024-08-02T03:50:55.993Z
Reserved: 2024-06-05T21:07:26.876Z
Link: CVE-2024-37346
Updated: 2024-06-25T15:24:56.451Z
Status : Modified
Published: 2024-06-20T17:15:51.623
Modified: 2024-11-21T09:23:41.620
Link: CVE-2024-37346
No data.
OpenCVE Enrichment
No data.
EUVD