Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-38334
HistoryJul 20, 2023 - 6:15 p.m.

Information disclosure

2023-07-2018:15:00
PRIOn knowledge base
www.prio-n.com
4
information disclosure
access control
irreversible operation
omnis studio 10.22.00
nvd

6.4 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

51.6%

Omnis Studio 10.22.00 has incorrect access control. It advertises an irreversible feature for locking classes within Omnis libraries: it should be no longer possible to delete, view, change, copy, rename, duplicate, or print a locked class. Due to implementation issues, locked classes in Omnis libraries can be unlocked, and thus further analyzed and modified by Omnis Studio. This allows for further analyzing and also deleting, viewing, changing, copying, renaming, duplicating, or printing previously locked Omnis classes. This violates the expected behavior of an “irreversible operation.”

CPENameOperatorVersion
studioeq10.22.00

6.4 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

51.6%

Related for PRION:CVE-2023-38334