Impact
Based on the description, a flaw in Combodo iTop’s search functionality appears to let an authenticated user access information about objects that they should not be able to see, allowing sensitive data exposure. The vulnerability is a direct breach of access control, classified under CWE‑862, and enables disclosure of data that can compromise the confidentiality of the organization’s asset inventory and IT services.
Affected Systems
All installations of Combodo iTop version 3.2.2 and earlier are affected; version 3.2.3 and later contain the fix and are not impacted.
Risk and Exploitability
The issue carries a CVSS score of 8.8, indicating high impact. No EPSS data is available and the vulnerability is not listed in KEV, suggesting current exploitation activity may be low. Based on the description, the likely attack vector is a web‑based request to the search endpoint; it is inferred that an attacker must have an authenticated account with view permissions to exploit the flaw.
OpenCVE Enrichment