First published: Tue Jan 24 2023(Updated: )
Ability to enumerate the Oracle LDAP attributes for the current user by modifying the query used by the application
Credit: secure@symantec.com
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom Symantec Identity Governance and Administration | =14.3 | |
Broadcom Symantec Identity Governance and Administration | =14.4.1 | |
Broadcom Symantec Identity Governance and Administration | =14.4.2 | |
Broadcom Symantec Identity Manager | =14.3 | |
Broadcom Symantec Identity Manager | =14.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-23951 is classified as a high severity vulnerability.
To fix CVE-2023-23951, upgrade to the latest version of the affected Broadcom Symantec Identity Governance and Administration or Identity Manager software.
The impact of CVE-2023-23951 allows attackers to enumerate LDAP attributes for the current user, potentially exposing sensitive information.
CVE-2023-23951 affects Broadcom Symantec Identity Governance and Administration versions 14.3, 14.4.1, and 14.4.2 and Symantec Identity Manager versions 14.3 and 14.4.
Yes, CVE-2023-23951 can be exploited remotely by attackers who can manipulate queries used by the affected application.