First published: Thu Sep 03 2020(Updated: )
A flaw was found in the Red Hat 3scale API Management Platform, where member permissions for an API's admin portal were not properly enforced. This flaw allows an authenticated user to bypass normal account restrictions and access API services where they do not have permission.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat 3scale Api Management | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this flaw is CVE-2020-14388.
The affected software is Red Hat 3scale API Management Platform version 2.0.
The severity of CVE-2020-14388 is medium with a severity value of 6.3.
This flaw allows an authenticated user to bypass normal account restrictions and access API services where they do not have permission.
Yes, a fix is available for CVE-2020-14388. Please refer to the reference link for more information.