Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allows Exploiting Incorrectly Configured Access Control Security Levels. Multiple missing permission checks - ALM job config has been discovered in OpenText Application Automation Tools. The vulnerability could allow users with Overall/Read permission to enumerate ALM server names, usernames and client IDs configured to be used with ALM servers. This issue affects OpenText Application Automation Tools: 24.1.0 and below.
History

Mon, 21 Oct 2024 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Microfocus
Microfocus application Automation Tools
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:microfocus:application_automation_tools:*:*:*:*:*:jenkins:*:*
Vendors & Products Microfocus
Microfocus application Automation Tools
Metrics cvssV3_1

{'score': 2.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N'}


Wed, 16 Oct 2024 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Oct 2024 17:00:00 +0000

Type Values Removed Values Added
Description Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allows Exploiting Incorrectly Configured Access Control Security Levels. Multiple missing permission checks - ALM job config has been discovered in OpenText Application Automation Tools. The vulnerability could allow users with Overall/Read permission to enumerate ALM server names, usernames and client IDs configured to be used with ALM servers. This issue affects OpenText Application Automation Tools: 24.1.0 and below.
Title Multiple missing permission checks
Weaknesses CWE-280
References
Metrics cvssV4_0

{'score': 1.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/S:N/AU:N/RE:L/U:Clear'}


cve-icon MITRE

Status: PUBLISHED

Assigner: OpenText

Published: 2024-10-16T16:41:20.927Z

Updated: 2024-10-16T18:54:06.989Z

Reserved: 2024-04-25T18:14:07.091Z

Link: CVE-2024-4211

cve-icon Vulnrichment

Updated: 2024-10-16T18:54:02.063Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-16T17:15:17.617

Modified: 2024-10-21T16:15:09.963

Link: CVE-2024-4211

cve-icon Redhat

No data.