Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-1604

Опубликовано: 18 мар. 2024
Источник: nvd
CVSS3: 6.4
CVSS3: 6.8
EPSS Низкий

Описание

Improper authorization in the report management and creation module of BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users to read and make unauthorized changes to any reports available within the application, even without proper permissions. The attacker must know the unique identifier of the report they want to manipulate.

Fix for 9.0.20 branch was released in version 9.0.20.238. Fix for 9.0.21 branch was released in version 9.0.21.201.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:bmc:control-m:*:*:*:*:*:*:*:*
Версия от 9.0.20 (включая) до 9.0.20.238 (исключая)
cpe:2.3:a:bmc:control-m:*:*:*:*:*:*:*:*
Версия от 9.0.21 (включая) до 9.0.21.201 (исключая)

EPSS

Процентиль: 21%
0.00068
Низкий

6.4 Medium

CVSS3

6.8 Medium

CVSS3

Дефекты

CWE-639
CWE-639

Связанные уязвимости

CVSS3: 6.4
github
почти 2 года назад

Improper authorization in the report management and creation module of BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users to read and make unauthorized changes to any reports available within the application, even without proper permissions. The attacker must know the unique identifier of the report they want to manipulate. Fix for 9.0.20 branch was released in version 9.0.20.238. Fix for 9.0.21 branch was released in version 9.0.21.201.

EPSS

Процентиль: 21%
0.00068
Низкий

6.4 Medium

CVSS3

6.8 Medium

CVSS3

Дефекты

CWE-639
CWE-639