Impact
Tanium issued a fix for an improper access controls vulnerability in Comply. The flaw allows a user with improper privileges to view or modify sensitive information that should be restricted, potentially leading to unauthorized data exposure.
Affected Systems
Affected vendor: Tanium. Affected product: Comply, version unspecified.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity. With no EPSS information and no listing in the CISA KEV catalog, the exploitation likelihood appears low, but the flaw still permits unauthorized access if an attacker gains a valid account. The likely attack vector is an authenticated internal user who bypasses access controls, inferred from the description of an improper access control issue.
OpenCVE Enrichment