PT-2004-1126 · Entrust · Entrust Authority Security Manager
Published
2004-01-14
·
Updated
2017-07-11
·
CVE-2002-0712
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Entrust Authority Security Manager (EASM) version 6.0
Description
The issue concerns the improper requirement for multiple master users to change the password of a master user. This could allow a master user to perform operations that require multiple authorizations.
Recommendations
For version 6.0, consider implementing a temporary workaround to enforce multiple authorizations for sensitive operations until a proper fix is available. As a mitigation measure, restrict the ability of a single master user to change passwords or perform critical operations without additional approvals.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Entrust Authority Security Manager