CVE-2024-25652: High severity delinea pam secret server vulnerability
In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with access to Report functionality via UNLIMITED ADMIN MODE (with access to the Report functionality) to gain unauthorized access to remote sessions created by legitimate users through information obtained from the Custom Legacy Report functionality.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25652?
CVE-2024-25652 is considered a high severity vulnerability due to the potential for unauthorized access to sensitive remote sessions.
How do I fix CVE-2024-25652?
To remediate CVE-2024-25652, ensure that user permissions for accessing the Report functionality are restricted appropriately.
Who is affected by CVE-2024-25652?
CVE-2024-25652 affects users of Delinea PAM Secret Server version 11.4 with access to the Report functionality.
What type of vulnerability is CVE-2024-25652?
CVE-2024-25652 is an authorization issue that allows unauthorized access to remote sessions.
Is there a workaround for CVE-2024-25652 while waiting for a patch?
A possible workaround for CVE-2024-25652 is to disable access to the Report functionality for unprivileged users until a patch is available.