PT-2023-23687 · Micro Focus · Enterprise Server Common Web Administration+6
Richard R Rohrkemper Iii
·
Publicado
2023-07-20
·
Atualizado
2023-07-31
·
CVE-2023-32265
CVSS v3.1
7.1
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Enterprise Server Common Web Administration (ESCWA) (affected versions not specified)
Description
A potential security issue has been identified in the ESCWA component used in several products, including Enterprise Server, Enterprise Test Server, Enterprise Developer, Visual COBOL, and COBOL Server. To exploit this issue, an attacker must be authenticated into ESCWA. The vulnerability could potentially expose a service account password, which usually has limited privileges. Mitigations such as restricting network access to ESCWA and limiting users' permissions in the Micro Focus Directory Server can reduce exposure to this issue.
Recommendations
As a temporary workaround, consider restricting network access to ESCWA and limiting users' permissions in the Micro Focus Directory Server to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Cobol Server
Enterprise Developer
Enterprise Server
Enterprise Server Common Web Administration
Enterprise Test Server
Micro Focus Directory Server
Visual Cobol