CVE-2024-33891: High severity delinea pam secret server vulnerability
Delinea Secret Server before 11.7.000001 allows attackers to bypass authentication via the SOAP API in SecretServer/webservices/SSWebService.asmx. This is related to a hardcoded key, the use of the integer 2 for the Admin user, and removal of the oauthExpirationId attribute.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-33891?
CVE-2024-33891 is considered a critical vulnerability due to its potential for unauthorized access to sensitive information.
How do I fix CVE-2024-33891?
To fix CVE-2024-33891, upgrade to Delinea Secret Server version 11.7.000001 or later.
What systems are affected by CVE-2024-33891?
CVE-2024-33891 affects Delinea Secret Server versions prior to 11.7.000001.
What is the exploit mechanism for CVE-2024-33891?
CVE-2024-33891 can be exploited via the SOAP API due to authentication bypass related to a hardcoded key.
Are there any known mitigations for CVE-2024-33891?
Currently, the only effective mitigation for CVE-2024-33891 is to apply the available software update to a patched version.