CVE-2020-29031: Insecure Direct Object Reference in GateManager WebUI can cause privilege escalation
An Insecure Direct Object Reference vulnerability exists in the web UI of the GateManager which allows an authenticated attacker to reset the password of any user in its domain or any sub-domain, via escalation of privileges. This issue affects all GateManager versions prior to 9.2c
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-29031?
CVE-2020-29031 is an Insecure Direct Object Reference vulnerability in the web UI of the GateManager which allows an authenticated attacker to reset the password of any user in its domain or any sub-domain, via escalation of privileges.
Which software versions are affected by CVE-2020-29031?
CVE-2020-29031 affects all GateManager versions prior to 9.2c.
What is the severity level of CVE-2020-29031?
CVE-2020-29031 has a severity level of 8.1 (High).
How can an attacker exploit CVE-2020-29031?
An attacker can exploit CVE-2020-29031 by gaining authenticated access to the GateManager web UI and then resetting the password of any user in its domain or any sub-domain.
How can I fix CVE-2020-29031?
To fix CVE-2020-29031, users are advised to upgrade to GateManager version 9.2c or later.