First published: Tue Feb 18 2025(Updated: )
Insecure Permissions in Atos Eviden IDRA and IDCA before 2.7.0. A highly trusted role (Config Admin) could exceed their configuration privileges in a multi-partition environment and access some confidential data. Data integrity and availability is not at risk.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Atos Eviden IDRA | <2.7.0 | |
Atos Eviden IDCA | <2.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-39328 is considered a high severity vulnerability due to its potential for privilege escalation.
To fix CVE-2024-39328, upgrade Atos Eviden IDRA and IDCA to version 2.7.0 or later.
CVE-2024-39328 is an insecure permissions vulnerability affecting the Config Admin role in a multi-partition environment.
The potential impact of CVE-2024-39328 includes the unauthorized access to confidential data, though data integrity and availability remain intact.
CVE-2024-39328 affects Atos Eviden IDRA and IDCA versions prior to 2.7.0.