Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-38334

Опубликовано: 20 июл. 2023
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

Omnis Studio 10.22.00 has incorrect access control. It advertises an irreversible feature for locking classes within Omnis libraries: it should be no longer possible to delete, view, change, copy, rename, duplicate, or print a locked class. Due to implementation issues, locked classes in Omnis libraries can be unlocked, and thus further analyzed and modified by Omnis Studio. This allows for further analyzing and also deleting, viewing, changing, copying, renaming, duplicating, or printing previously locked Omnis classes. This violates the expected behavior of an "irreversible operation."

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:omnis:studio:10.22.00:*:*:*:*:*:*:*

EPSS

Процентиль: 40%
0.00186
Низкий

6.5 Medium

CVSS3

Дефекты

NVD-CWE-Other
CWE-276

Связанные уязвимости

CVSS3: 6.5
github
больше 2 лет назад

Omnis Studio 10.22.00 has incorrect access control. It advertises an irreversible feature for locking classes within Omnis libraries: it should be no longer possible to delete, view, change, copy, rename, duplicate, or print a locked class. Due to implementation issues, locked classes in Omnis libraries can be unlocked, and thus further analyzed and modified by Omnis Studio. This allows for further analyzing and also deleting, viewing, changing, copying, renaming, duplicating, or printing previously locked Omnis classes. This violates the expected behavior of an "irreversible operation."

EPSS

Процентиль: 40%
0.00186
Низкий

6.5 Medium

CVSS3

Дефекты

NVD-CWE-Other
CWE-276