CVSS2
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Authentication
SINGLE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:A/AC:L/Au:S/C:P/I:P/A:N
CVSS3
Attack Vector
ADJACENT
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
AI Score
Confidence
High
EPSS
Percentile
12.6%
For MongoDB Ops Manager versions prior to and including 4.2.24 with
multiple OM application servers, that have SSL turned on for their MongoDB
processes, the upgrade to MongoDB Ops Manager versions prior to and
including 4.4.12 triggers a bug where Automation thinks SSL is being turned
off, and can disable SSL temporarily for members of the cluster. This issue
is temporary and eventually corrects itself after MongoDB Ops Manager
instances have finished upgrading to MongoDB Ops Manager 4.4. In addition,
customers must be running with clientCertificateMode=OPTIONAL /
allowConnectionsWithoutCertificates=true to be impacted*.* Customers
upgrading from Ops Manager 4.2.X to 4.2.24 and finally to Ops Manager
4.4.13+ are unaffected by this issue.
CVSS2
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Authentication
SINGLE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:A/AC:L/Au:S/C:P/I:P/A:N
CVSS3
Attack Vector
ADJACENT
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
AI Score
Confidence
High
EPSS
Percentile
12.6%