CVE-2023-7248: OpenText Vertica Management console might be prone to bypass via crafted requests
Certain functionality in OpenText Vertica Management console might be prone to bypass via crafted requests.
The vulnerability would affect one of Vertica’s authentication functionalities by allowing specially crafted requests and sequences. This issue impacts the following Vertica Management Console versions: 10.x 11.1.1-24 or lower 12.0.4-18 or lower
Please upgrade to one of the following Vertica Management Console versions: 10.x to upgrade to latest versions from below. 11.1.1-25 12.0.4-19 23.x 24.x
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-7248?
CVE-2023-7248 is classified as a medium severity vulnerability that could allow for authentication bypass in OpenText Vertica.
How do I fix CVE-2023-7248?
To fix CVE-2023-7248, you should upgrade OpenText Vertica to a version that is not affected, specifically to versions above 10.1.1-26, 11.1.1-25, or 12.0.4-19.
What versions of OpenText Vertica are affected by CVE-2023-7248?
CVE-2023-7248 affects OpenText Vertica versions from 10.0.0-0 up to 10.1.1-26, 11.0.0-0 up to 11.1.1-25, and 12.0.0-0 up to 12.0.4-19.
What impact does CVE-2023-7248 have on OpenText Vertica?
CVE-2023-7248 may allow attackers to bypass authentication controls, potentially leading to unauthorized access.
Is CVE-2023-7248 being actively exploited?
As of now, there is no public evidence to suggest that CVE-2023-7248 is actively being exploited in the wild.