There is an insufficient input validation vulnerability in the Warehouse component of Absolute Secure Access prior to 13.06. Attackers with system administrator permissions can impair the availability of certain elements of the Secure Access administrative UI by writing invalid data to the warehouse over the network. There is no loss of warehouse integrity or confidentiality, the security scope is unchanged. Loss of availability is high.
History

Wed, 07 Aug 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Absolute
Absolute secure Access
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:*
Vendors & Products Absolute
Absolute secure Access

cve-icon MITRE

Status: PUBLISHED

Assigner: Absolute

Published: 2024-06-20T16:51:37.265Z

Updated: 2024-08-02T03:50:55.993Z

Reserved: 2024-06-05T21:07:26.876Z

Link: CVE-2024-37346

cve-icon Vulnrichment

Updated: 2024-06-25T15:24:56.451Z

cve-icon NVD

Status : Analyzed

Published: 2024-06-20T17:15:51.623

Modified: 2024-08-07T16:47:56.807

Link: CVE-2024-37346

cve-icon Redhat

No data.