PT-2024-32283 · Opentext · Opentext Application Automation Tools
Published
2024-10-16
·
Updated
2024-10-21
·
CVE-2024-4692
CVSS v3.1
2.4
Low
| Vector | AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenText Application Automation Tools versions 24.1.0 and below
Description
The issue is related to improper validation of specified quantity in input, allowing exploitation of incorrectly configured access control security levels. Multiple missing permission checks have been discovered in the Service Virtualization configuration, which could allow users with Overall/Read permission to enumerate Service Virtualization server names.
Recommendations
For OpenText Application Automation Tools versions 24.1.0 and below, update to a version above 24.1.0 to resolve the issue.
As a temporary workaround, consider restricting access to the Service Virtualization configuration to minimize the risk of exploitation.
Avoid using the Overall/Read permission for users who do not require it, until the issue is resolved.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opentext Application Automation Tools