First published: Thu Mar 21 2024(Updated: )
Weak access control in OpenText PVCS Version Manager allows potential bypassing of authentication and uploading of files.
Credit: security@opentext.com
Affected Software | Affected Version | How to fix |
---|---|---|
PVCS Version Manager |
https://portal.microfocus.com/s/article/KM000026669
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-1148 has been classified as a critical vulnerability due to weak access controls.
To remediate CVE-2024-1148, update to the latest version of OpenText PVCS Version Manager where access control issues have been addressed.
CVE-2024-1148 can be exploited for unauthorized file uploads and potential authentication bypass.
CVE-2024-1148 affects multiple versions of OpenText PVCS Version Manager prior to the latest patch.
Currently, the primary recommendation for CVE-2024-1148 is to upgrade to the patched version as there are no specific workarounds available.