RapidIdentity LTS through 2023.0.2 and Cloud through 2024.08.0 improperly restricts excessive authentication attempts and allows a remote attacker to cause a denial of service via the username parameters.
History

Thu, 12 Sep 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Identityautomation rapididentity
CPEs cpe:2.3:a:identityautomation:rapididentity:*:*:*:*:cloud:*:*:*
cpe:2.3:a:identityautomation:rapididentity:*:*:*:*:lts:*:*:*
Vendors & Products Identityautomation rapididentity

Thu, 05 Sep 2024 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Identityautomation
Identityautomation rapididentity Cloud
Identityautomation rapididentity Lts
Weaknesses CWE-307
CPEs cpe:2.3:a:identityautomation:rapididentity_cloud:*:*:*:*:*:*:*:*
cpe:2.3:a:identityautomation:rapididentity_lts:*:*:*:*:*:*:*:*
Vendors & Products Identityautomation
Identityautomation rapididentity Cloud
Identityautomation rapididentity Lts
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 05 Sep 2024 16:15:00 +0000

Type Values Removed Values Added
Description RapidIdentity LTS through 2023.0.2 and Cloud through 2024.08.0 improperly restricts excessive authentication attempts and allows a remote attacker to cause a denial of service via the username parameters.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-09-05T00:00:00

Updated: 2024-09-05T18:00:23.316Z

Reserved: 2024-09-02T00:00:00

Link: CVE-2024-45589

cve-icon Vulnrichment

Updated: 2024-09-05T17:57:10.868Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-05T16:15:08.737

Modified: 2024-09-12T16:54:09.467

Link: CVE-2024-45589

cve-icon Redhat

No data.