CVE-2024-1148: Weak Access Control - Arbitrary file upload
Published Mar 21, 2024
·Updated
Weak access control in OpenText PVCS Version Manager allows potential bypassing of authentication and uploading of files.
Affected Software
1 affected component
OpenText PVCS Version Manager
Remediation
Information
https://portal.microfocus.com/s/article/KM000026669
Event History
Mar 21, 2024
CVE Published
via MITRE·07:34 AM
Data Sourced
via MITRE·07:34 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-1148?
CVE-2024-1148 has been classified as a critical vulnerability due to weak access controls.
2
How do I fix CVE-2024-1148?
To remediate CVE-2024-1148, update to the latest version of OpenText PVCS Version Manager where access control issues have been addressed.
3
What types of attacks can exploit CVE-2024-1148?
CVE-2024-1148 can be exploited for unauthorized file uploads and potential authentication bypass.
4
Which versions of OpenText PVCS Version Manager are affected by CVE-2024-1148?
CVE-2024-1148 affects multiple versions of OpenText PVCS Version Manager prior to the latest patch.
5
Is there any workaround for CVE-2024-1148?
Currently, the primary recommendation for CVE-2024-1148 is to upgrade to the patched version as there are no specific workarounds available.