CVE-2024-1147: Weak Access Control - Arbitrary file download
Published Mar 21, 2024
·Updated
Weak access control in OpenText PVCS Version Manager allows potential bypassing of authentication and download of files.
Affected Software
1 affected component
OpenText PVCS Version Manager
Remediation
Information
https://portal.microfocus.com/s/article/KM000026669
Event History
Mar 21, 2024
CVE Published
via MITRE·07:33 AM
Data Sourced
via MITRE·07:33 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-1147?
CVE-2024-1147 has been rated as a high severity vulnerability due to its potential for unauthorized access and file downloads.
2
How do I fix CVE-2024-1147?
To fix CVE-2024-1147, ensure that you apply the latest security patches provided by OpenText for PVCS Version Manager.
3
What type of vulnerability is CVE-2024-1147?
CVE-2024-1147 is an access control vulnerability that allows bypassing of authentication.
4
What could be the impact of CVE-2024-1147?
The impact of CVE-2024-1147 could result in unauthorized users downloading sensitive files from the system.
5
Is CVE-2024-1147 specific to any version of OpenText PVCS Version Manager?
CVE-2024-1147 affects OpenText PVCS Version Manager but specific version details are not disclosed in the current description.