CVE-2024-11923: Sensitive Information Disclosure in Fortra Application Hub Prior to version 1.3
Published Jan 17, 2025
·Updated
Under certain log settings the IAM or CORE service will log credentials in the iam logfile in Fortra Application Hub (Formerly named Helpsystems One) prior to version 1.3
Affected Software
1 affected component
Fortra Application Hub<1.3
Remediation
Information
Upgrade to Fortra Application Hub 1.3 or higher.
Event History
Jan 17, 2025
CVE Published
via MITRE·11:44 PM
Data Sourced
via MITRE·11:44 PM
RemedyDescriptionSeverityWeakness
Jan 18, 2025
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-11923?
CVE-2024-11923 is classified as a high-severity vulnerability due to potential exposure of sensitive credentials.
2
How do I fix CVE-2024-11923?
To fix CVE-2024-11923, upgrade to Fortra Application Hub version 1.3 or later.
3
What systems are affected by CVE-2024-11923?
CVE-2024-11923 affects Fortra Application Hub versions prior to 1.3.
4
What type of information can be leaked through CVE-2024-11923?
CVE-2024-11923 can leak credentials logged in the IAM logfile under certain log settings.
5
What could be the impact of exploiting CVE-2024-11923?
Exploiting CVE-2024-11923 could lead to unauthorized access due to exposed sensitive credentials.