CVE-2023-47298: Infoleak
An issue in NCR Terminal Handler 1.5.1 allows a low-level privileged authenticated attacker to query the SOAP API endpoint to obtain information about all of the users of the application including their usernames, roles, security groups and account statuses.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-47298?
CVE-2023-47298 is considered a high severity vulnerability due to the unauthorized access it allows to sensitive user information.
How do I fix CVE-2023-47298?
To mitigate CVE-2023-47298, it is recommended to update NCR Terminal Handler to the latest version and restrict access to the SOAP API.
What type of attack does CVE-2023-47298 allow?
CVE-2023-47298 allows low-level privileged authenticated attackers to query sensitive user data through the SOAP API.
What information can be accessed through CVE-2023-47298?
CVE-2023-47298 enables attackers to access usernames, roles, security groups, and account statuses of all users within the application.
Who is affected by CVE-2023-47298?
CVE-2023-47298 affects users of NCR Terminal Handler version 1.5.1 and may impact organizations relying on this software for user management.