PT-2024-32283 · Opentext · Opentext Application Automation Tools

Published

2024-10-16

·

Updated

2024-10-21

·

CVE-2024-4692

CVSS v3.1

2.4

Low

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenText Application Automation Tools versions 24.1.0 and below
Description The issue is related to improper validation of specified quantity in input, allowing exploitation of incorrectly configured access control security levels. Multiple missing permission checks have been discovered in the Service Virtualization configuration, which could allow users with Overall/Read permission to enumerate Service Virtualization server names.
Recommendations For OpenText Application Automation Tools versions 24.1.0 and below, update to a version above 24.1.0 to resolve the issue. As a temporary workaround, consider restricting access to the Service Virtualization configuration to minimize the risk of exploitation. Avoid using the Overall/Read permission for users who do not require it, until the issue is resolved.

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-4692

Affected Products

Opentext Application Automation Tools