mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-07-09 16:05:11 +00:00
78 lines
2.9 KiB
JSON
78 lines
2.9 KiB
JSON
![]() |
{
|
||
|
"id": "CVE-2024-12799",
|
||
|
"sourceIdentifier": "security@opentext.com",
|
||
|
"published": "2025-03-05T15:15:13.127",
|
||
|
"lastModified": "2025-03-05T15:15:13.127",
|
||
|
"vulnStatus": "Received",
|
||
|
"cveTags": [],
|
||
|
"descriptions": [
|
||
|
{
|
||
|
"lang": "en",
|
||
|
"value": "Insufficiently Protected Credentials\nvulnerability in OpenText Identity Manager Advanced Edition on Windows, Linux,\n64 bit allows Privilege Abuse. This vulnerability could allow an\nauthenticated user to obtain higher privileged user\u2019s sensitive information via\ncrafted payload.\n\nThis issue affects Identity Manager Advanced\nEdition: from 4.8.0.0 through 4.8.7.0102, 4.9.0.0."
|
||
|
}
|
||
|
],
|
||
|
"metrics": {
|
||
|
"cvssMetricV40": [
|
||
|
{
|
||
|
"source": "security@opentext.com",
|
||
|
"type": "Secondary",
|
||
|
"cvssData": {
|
||
|
"version": "4.0",
|
||
|
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:U/V:C/RE:H/U:Red",
|
||
|
"baseScore": 10.0,
|
||
|
"baseSeverity": "CRITICAL",
|
||
|
"attackVector": "NETWORK",
|
||
|
"attackComplexity": "LOW",
|
||
|
"attackRequirements": "NONE",
|
||
|
"privilegesRequired": "NONE",
|
||
|
"userInteraction": "NONE",
|
||
|
"vulnConfidentialityImpact": "HIGH",
|
||
|
"vulnIntegrityImpact": "HIGH",
|
||
|
"vulnAvailabilityImpact": "HIGH",
|
||
|
"subConfidentialityImpact": "HIGH",
|
||
|
"subIntegrityImpact": "HIGH",
|
||
|
"subAvailabilityImpact": "HIGH",
|
||
|
"exploitMaturity": "NOT_DEFINED",
|
||
|
"confidentialityRequirement": "NOT_DEFINED",
|
||
|
"integrityRequirement": "NOT_DEFINED",
|
||
|
"availabilityRequirement": "NOT_DEFINED",
|
||
|
"modifiedAttackVector": "NOT_DEFINED",
|
||
|
"modifiedAttackComplexity": "NOT_DEFINED",
|
||
|
"modifiedAttackRequirements": "NOT_DEFINED",
|
||
|
"modifiedPrivilegesRequired": "NOT_DEFINED",
|
||
|
"modifiedUserInteraction": "NOT_DEFINED",
|
||
|
"modifiedVulnConfidentialityImpact": "NOT_DEFINED",
|
||
|
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
|
||
|
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
|
||
|
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
|
||
|
"modifiedSubIntegrityImpact": "NOT_DEFINED",
|
||
|
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
|
||
|
"Safety": "PRESENT",
|
||
|
"Automatable": "YES",
|
||
|
"Recovery": "USER",
|
||
|
"valueDensity": "CONCENTRATED",
|
||
|
"vulnerabilityResponseEffort": "HIGH",
|
||
|
"providerUrgency": "RED"
|
||
|
}
|
||
|
}
|
||
|
]
|
||
|
},
|
||
|
"weaknesses": [
|
||
|
{
|
||
|
"source": "security@opentext.com",
|
||
|
"type": "Primary",
|
||
|
"description": [
|
||
|
{
|
||
|
"lang": "en",
|
||
|
"value": "CWE-522"
|
||
|
}
|
||
|
]
|
||
|
}
|
||
|
],
|
||
|
"references": [
|
||
|
{
|
||
|
"url": "https://portal.microfocus.com/s/article/KM000037455",
|
||
|
"source": "security@opentext.com"
|
||
|
}
|
||
|
]
|
||
|
}
|