CVE-2023-7240: Broken Access Control leading to SSRF in NetIQ Identity Console
An improper authorization level has been detected in the login panel. It may lead to unauthenticated Server Side Request Forgery and allows to perform open services enumeration. Server makes query to provided server (Server IP/DNS field) and is triggering connection to arbitrary address.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-7240?
CVE-2023-7240 has a high severity due to the potential for unauthenticated server-side request forgery.
How do I fix CVE-2023-7240?
To fix CVE-2023-7240, update to the latest version of Micro Focus NetIQ Identity Console, which addresses this vulnerability.
What impact does CVE-2023-7240 have on my system?
CVE-2023-7240 may allow attackers to perform unauthorized open services enumeration and connect to arbitrary systems.
What systems are affected by CVE-2023-7240?
CVE-2023-7240 specifically affects Micro Focus NetIQ Identity Console.
Is CVE-2023-7240 being exploited in the wild?
As of now, there is no public information indicating that CVE-2023-7240 is actively being exploited in the wild.