216.73.216.133

CVE-2024-4692

· Published 16/10/2024 17:15 · Modified 21/10/2024 16:10

Labels: CVE-2024-4692 2024-10-16CVE-2024-4692CWE-280NVD-CWE-noinfo[email protected]

Essential information

Published
16/10/2024 17:15
Modified
21/10/2024 16:10
Author
Creator
CVSS
2.4 LOW (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N

CVSS metrics

Description

Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allows Exploiting Incorrectly Configured Access Control Security Levels. Multiple missing permission checks - Service Virtualization config has been discovered in in OpenText Application Automation Tools. The vulnerability could allow users with Overall/Read permission to enumerate Service Virtualization server names. This issue affects OpenText Application Automation Tools: 24.1.0 and below.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
microfocus / application automation tools cpe:2.3:a:microfocus:application_automation_tools:*:*:*:*:*:jenkins:*:*

References