Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-55000 | iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, anyone with an account having portal access can have read access to objects they're not allowed to see by querying an unprotected route. Versions 2.7.12, 3.1.3, and 3.2.1 contain a fix for the issue. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 01 Aug 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:* |
Wed, 14 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 14 May 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, anyone with an account having portal access can have read access to objects they're not allowed to see by querying an unprotected route. Versions 2.7.12, 3.1.3, and 3.2.1 contain a fix for the issue. | |
| Title | iTop portal Insecure Direct Object Reference vulnerability | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-05-14T14:49:38.783Z
Reserved: 2024-11-14T15:05:46.770Z
Link: CVE-2024-52601
Updated: 2025-05-14T14:49:32.555Z
Status : Analyzed
Published: 2025-05-14T15:15:55.200
Modified: 2025-08-01T18:39:53.140
Link: CVE-2024-52601
No data.
OpenCVE Enrichment
Updated: 2025-07-12T16:01:35Z
EUVD