Orca HCM from LEARNING DIGITAL does not properly restrict access to a specific functionality, allowing unauthenticated remote attacker to exploit this functionality to create an account with administrator privilege and subsequently use it to log in. ( The vendor is currently addressing the vulnerability. Once the fix is completed, we will provide information on the affected versions.)
History

Fri, 13 Sep 2024 09:45:00 +0000

Type Values Removed Values Added
Description Orca HCM from LEARNING DIGITAL does not properly restrict access to a specific functionality, allowing unauthenticated remote attacker to exploit this functionality to create an account with administrator privilege and subsequently use it to log in. Orca HCM from LEARNING DIGITAL does not properly restrict access to a specific functionality, allowing unauthenticated remote attacker to exploit this functionality to create an account with administrator privilege and subsequently use it to log in. ( The vendor is currently addressing the vulnerability. Once the fix is completed, we will provide information on the affected versions.)

Wed, 11 Sep 2024 16:15:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-Other

Mon, 09 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Learningdigital
Learningdigital orca Hcm
CPEs cpe:2.3:a:learningdigital:orca_hcm:*:*:*:*:*:*:*:*
Vendors & Products Learningdigital
Learningdigital orca Hcm
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 09 Sep 2024 03:15:00 +0000

Type Values Removed Values Added
Description Orca HCM from LEARNING DIGITAL does not properly restrict access to a specific functionality, allowing unauthenticated remote attacker to exploit this functionality to create an account with administrator privilege and subsequently use it to log in.
Title LEARNING DIGITAL Orca HCM - Improper Access Control
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2024-09-09T02:57:22.560Z

Updated: 2024-09-13T09:33:00.287Z

Reserved: 2024-09-09T02:28:07.857Z

Link: CVE-2024-8584

cve-icon Vulnrichment

Updated: 2024-09-09T13:40:39.001Z

cve-icon NVD

Status : Modified

Published: 2024-09-09T03:15:09.723

Modified: 2024-09-13T10:15:17.263

Link: CVE-2024-8584

cve-icon Redhat

No data.