PT-2023-13712 · Comodo+1 · Itop+1

Blaklis

+1

·

Published

2023-03-14

·

Updated

2024-04-04

·

CVE-2022-39214

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Combodo iTop versions prior to 2.7.8 Combodo iTop versions prior to 3.0.2-1
Description The issue allows a user who can log in to take over any account by knowing the account's username.
Recommendations For versions prior to 2.7.8, update to version 2.7.8 or later. For versions prior to 3.0.2-1, update to version 3.0.2-1 or later.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1879
ALT-PU-2024-4537
ALT-PU-2024-4547
ALT-PU-2024-4961
CVE-2022-39214
GHSA-VJ96-J84G-JHX4

Affected Products

Alt Linux
Itop