PT-2024-37565 · Opentext · Opentext Vertica
Published
2024-10-02
·
Updated
2025-11-19
·
CVE-2024-6360
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenText Vertica versions 10.0 through 10.X
OpenText Vertica versions 11.0 through 11.X
OpenText Vertica versions 12.0 through 12.X
OpenText Vertica versions 23.0 through 23.X
OpenText Vertica versions 24.0 through 24.X
Description
The issue is related to an Incorrect Permission Assignment for Critical Resource vulnerability, which could allow Privilege Abuse and result in unauthorized access or privileges to the Vertica agent
apikey.Recommendations
For versions 10.0 through 10.X, update to a version that fixes the Incorrect Permission Assignment issue.
For versions 11.0 through 11.X, update to a version that fixes the Incorrect Permission Assignment issue.
For versions 12.0 through 12.X, update to a version that fixes the Incorrect Permission Assignment issue.
For versions 23.0 through 23.X, update to a version that fixes the Incorrect Permission Assignment issue.
For versions 24.0 through 24.X, update to a version that fixes the Incorrect Permission Assignment issue.
As a temporary workaround, consider restricting access to the Vertica agent
apikey to minimize the risk of exploitation.Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opentext Vertica