PT-2018-18201 · Netiq · Netiq Sentinel

Publicado

2018-03-07

·

Atualizado

2021-04-13

·

CVE-2018-7675

CVSS v3.1

5.3

Média

VetorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions NetIQ Sentinel versions prior to 8.1.x
Description The issue occurs when a Sentinel user is logged into the Sentinel Web Interface, performs tasks, and then goes idle for a period, causing the interface to timeout. If another user logs in without the first user logging out, their credentials are accepted, allowing them to view the previous screen. This may potentially expose another user's events or configuration information.
Recommendations For versions prior to 8.1.x, update to version 8.1.x or later to resolve the issue. As a temporary workaround, consider implementing a policy that requires users to log out when finished using the Sentinel Web Interface to prevent unauthorized access to sensitive information. Additionally, restrict access to sensitive views or configuration information to minimize the risk of exposure.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-7675

Produtos afetados

Netiq Sentinel