PT-2023-13712 · Comodo+1 · Itop+1

·

CVE-2022-39214

·

Published

2023-03-14

·

Updated

2024-04-04

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Combodo iTop versions prior to 2.7.8 Combodo iTop versions prior to 3.0.2-1
Description The issue allows a user who can log in to take over any account by knowing the account's username.
Recommendations For versions prior to 2.7.8, update to version 2.7.8 or later. For versions prior to 3.0.2-1, update to version 3.0.2-1 or later.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1879
ALT-PU-2024-4537
ALT-PU-2024-4547
ALT-PU-2024-4961
CVE-2022-39214
GHSA-VJ96-J84G-JHX4

Affected Products

Alt Linux
Itop