CVE-2023-35998 - CERT CVE
ID CVE-2023-35998
Sažetak A missing authorization check in multiple SOAP endpoints of the Insider Threat Management Server enables an attacker on an adjacent network to read and write unauthorized objects. Successful exploitation requires an attacker to first obtain a valid agent authentication token. All versions before 7.14.3 are affected.
Reference
CVSS
Base: 4.6
Impact: 2.5
Exploitability:2.1
Pristup
VektorSloženostAutentikacija
ADJACENT_NETWORK LOW -
Impact
PovjerljivostCjelovitostDostupnost
LOW LOW NONE
CVSS vektor CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Zadnje važnije ažuriranje 06-07-2023 - 15:38
Objavljeno 27-06-2023 - 15:15