First published: Wed Jan 14 2004(Updated: )
Entrust Authority Security Manager (EASM) 6.0 does not properly require multiple master users to change the password of a master user, which could allow a master user to perform operations that require multiple authorizations.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Entrust Authority Security Manager | =6.0 | |
Entrust Authority Security Manager | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0712 is a moderate severity vulnerability due to improper authorization requirements for password changes.
To mitigate CVE-2002-0712, ensure that multiple master user approvals are required for password changes.
CVE-2002-0712 affects Entrust Authority Security Manager versions 5.0 and 6.0.
CVE-2002-0712 poses risks by allowing a master user to perform unauthorized operations due to insufficient validation.
A possible workaround for CVE-2002-0712 is to implement heightened internal controls around master user account management.