Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Richard R Rohrkemper Iii

Researcher fromEarly Warning Security
#39155of 53,633
7.1Total CVSS
Vulnerabilities · 1
PT-2023-23687
7.1
2023-07-20
Micro Focus · Enterprise Server Common Web Administration · CVE-2023-32265
**Name of the Vulnerable Software and Affected Versions** Enterprise Server Common Web Administration (ESCWA) (affected versions not specified) **Description** A potential security issue has been identified in the ESCWA component used in several products, including Enterprise Server, Enterprise Test Server, Enterprise Developer, Visual COBOL, and COBOL Server. To exploit this issue, an attacker must be authenticated into ESCWA. The vulnerability could potentially expose a service account password, which usually has limited privileges. Mitigations such as restricting network access to ESCWA and limiting users' permissions in the Micro Focus Directory Server can reduce exposure to this issue. **Recommendations** As a temporary workaround, consider restricting network access to ESCWA and limiting users' permissions in the Micro Focus Directory Server to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.