Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q8jc-hpcv-jmxw

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows OTP bypass via vectors involving a man in the middle, the One Identity Defender product, and replacing a failed SAML response with a successful SAML response.

One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows OTP bypass via vectors involving a man in the middle, the One Identity Defender product, and replacing a failed SAML response with a successful SAML response.

EPSS

Процентиль: 70%
0.00633
Низкий

8.1 High

CVSS3

Дефекты

CWE-354

Связанные уязвимости

CVSS3: 8.1
nvd
больше 6 лет назад

One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows OTP bypass via vectors involving a man in the middle, the One Identity Defender product, and replacing a failed SAML response with a successful SAML response.

EPSS

Процентиль: 70%
0.00633
Низкий

8.1 High

CVSS3

Дефекты

CWE-354