CVE-2024-25653: Medium severity delinea pam secret server vulnerability
Broken Access Control in the Report functionality of Delinea PAM Secret Server 11.4 allows unprivileged users, when Unlimited Admin Mode is enabled, to view system reports and modify custom reports via the Report functionality in the Web UI.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25653?
CVE-2024-25653 has been assigned a high severity rating due to its potential to allow unprivileged users to access sensitive reports and modify them.
How do I fix CVE-2024-25653?
To mitigate CVE-2024-25653, ensure that Unlimited Admin Mode is disabled and implement stricter access controls for report functionalities.
Who is affected by CVE-2024-25653?
CVE-2024-25653 affects users of Delinea PAM Secret Server 11.4 with Unlimited Admin Mode enabled.
What can attackers do with CVE-2024-25653?
Attackers can exploit CVE-2024-25653 to access and modify sensitive report data without proper permissions.
Is there a patch available for CVE-2024-25653?
Currently, there is no specific patch for CVE-2024-25653, but users should follow best practices to secure their configurations.