PT-2018-18201 · Netiq · Netiq Sentinel

Published

2018-03-07

·

Updated

2021-04-13

·

CVE-2018-7675

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions NetIQ Sentinel versions prior to 8.1.x
Description The issue occurs when a Sentinel user is logged into the Sentinel Web Interface, performs tasks, and then goes idle for a period, causing the interface to timeout. If another user logs in without the first user logging out, their credentials are accepted, allowing them to view the previous screen. This may potentially expose another user's events or configuration information.
Recommendations For versions prior to 8.1.x, update to version 8.1.x or later to resolve the issue. As a temporary workaround, consider implementing a policy that requires users to log out when finished using the Sentinel Web Interface to prevent unauthorized access to sensitive information. Additionally, restrict access to sensitive views or configuration information to minimize the risk of exposure.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-7675

Affected Products

Netiq Sentinel