PT-2019-12461 · Micro Focus+1 · Content Manager+1
Publicado
2019-08-29
·
Atualizado
2019-08-30
·
CVE-2019-11658
CVSS v3.1
4.3
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Micro Focus Content Manager versions 9.1 through 9.3
Description
The issue allows valid system users to access a limited subset of records they would not normally be able to access when the system is in an abnormal state. This occurs when the system is configured to use an Oracle database.
Recommendations
For versions 9.1 through 9.3, consider restricting access to sensitive records until a fix is available. As a temporary workaround, review system configurations and user permissions to minimize the risk of unauthorized access.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Content Manager
Oracle Database