PT-2024-37565 · Opentext · Opentext Vertica

Published

2024-10-02

·

Updated

2025-11-19

·

CVE-2024-6360

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenText Vertica versions 10.0 through 10.X OpenText Vertica versions 11.0 through 11.X OpenText Vertica versions 12.0 through 12.X OpenText Vertica versions 23.0 through 23.X OpenText Vertica versions 24.0 through 24.X
Description The issue is related to an Incorrect Permission Assignment for Critical Resource vulnerability, which could allow Privilege Abuse and result in unauthorized access or privileges to the Vertica agent apikey.
Recommendations For versions 10.0 through 10.X, update to a version that fixes the Incorrect Permission Assignment issue. For versions 11.0 through 11.X, update to a version that fixes the Incorrect Permission Assignment issue. For versions 12.0 through 12.X, update to a version that fixes the Incorrect Permission Assignment issue. For versions 23.0 through 23.X, update to a version that fixes the Incorrect Permission Assignment issue. For versions 24.0 through 24.X, update to a version that fixes the Incorrect Permission Assignment issue. As a temporary workaround, consider restricting access to the Vertica agent apikey to minimize the risk of exploitation.

Fix

Incorrect Permission

Weakness Enumeration

Related Identifiers

CVE-2024-6360

Affected Products

Opentext Vertica