Lucene search

K
cveMitreCVE-2023-49961
HistoryJan 08, 2024 - 9:15 p.m.

CVE-2023-49961

2024-01-0821:15:08
mitre
web.nvd.nist.gov
22
wallix
bastion
access manager
7.x
8.x
9.x
10.x
nvd
cve-2023-49961
incorrect access control
sensitive data exposure

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

37.2%

WALLIX Bastion 7.x, 8.x, 9.x and 10.x and WALLIX Access Manager 3.x and 4.x have Incorrect Access Control which can lead to sensitive data exposure.

Affected configurations

Nvd
Node
wallixbastionRange7.0.09.0.10
OR
wallixbastionRange10.0.010.0.6
OR
wallixbastionRange10.4.010.4.2
OR
wallixbastion_access_managerRange3.0.04.0.3
VendorProductVersionCPE
wallixbastion*cpe:2.3:a:wallix:bastion:*:*:*:*:*:*:*:*
wallixbastion_access_manager*cpe:2.3:a:wallix:bastion_access_manager:*:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

37.2%

Related for CVE-2023-49961