CVE-2024-37346: Insufficient input validation vulnerability in the Absolute Secure Access Warehouse prior to 13.06
There is an insufficient input validation vulnerability in the Warehouse component of Absolute Secure Access prior to 13.06. Attackers with system administrator permissions can impair the availability of certain elements of the Secure Access administrative UI by writing invalid data to the warehouse over the network. There is no loss of warehouse integrity or confidentiality, the security scope is unchanged. Loss of availability is high.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37346?
CVE-2024-37346 has a high severity rating due to its potential impact on the availability of the Secure Access administrative UI.
How do I fix CVE-2024-37346?
To fix CVE-2024-37346, upgrade Absolute Secure Access to version 13.06 or later.
Who is affected by CVE-2024-37346?
CVE-2024-37346 affects systems running any version of Absolute Secure Access prior to 13.06.
What are the implications of CVE-2024-37346 for system administrators?
System administrators with insufficient input validation can inadvertently compromise the availability of the Secure Access administrative UI.
Can CVE-2024-37346 be exploited remotely?
Yes, CVE-2024-37346 can potentially be exploited by attackers with system administrator permissions.