First published: Fri Dec 16 2022(Updated: )
An unauthenticated user can access Identity Manager’s management console specific page URLs. However, the system doesn’t allow the user to carry out server side tasks without a valid web session.
Credit: secure@symantec.com
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom Symantec Identity Governance and Administration | =14.3 | |
Broadcom Symantec Identity Governance and Administration | =14.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-25626 has a moderate severity rating due to potential unauthorized access to specific management console URLs.
To remediate CVE-2022-25626, ensure proper session management and implement authentication mechanisms for accessing management console URLs.
CVE-2022-25626 affects users of Broadcom Symantec Identity Governance and Administration versions 14.3 and 14.4.
CVE-2022-25626 allows an unauthenticated user to enumerate specific management console page URLs, although not to perform sensitive actions.
Yes, while CVE-2022-25626 allows access to certain URLs, it does not permit execution of server-side tasks without a valid web session.