First published: Wed Oct 16 2024(Updated: )
Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allows Exploiting Incorrectly Configured Access Control Security Levels. Multiple missing permission checks - Service Virtualization config has been discovered in in OpenText Application Automation Tools. The vulnerability could allow users with Overall/Read permission to enumerate Service Virtualization server names. This issue affects OpenText Application Automation Tools: 24.1.0 and below.
Credit: security@opentext.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microfocus Application Automation Tools | <24.1.0 |
Upgrade to version 24.2 or above of OpenText Application Automation Tools addresses this vulnerability:
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-4692 has been classified as a high-severity vulnerability due to its potential for allowing unauthorized access.
To fix CVE-2024-4692, ensure that proper permission checks are configured and applied to your OpenText Application Automation Tools.
CVE-2024-4692 affects versions of Microfocus Application Automation Tools up to but not including 24.1.0.
The impact of CVE-2024-4692 includes the potential exploitation of incorrectly configured access control security levels.
Organizations using Microfocus Application Automation Tools that have not implemented proper security configurations are vulnerable to CVE-2024-4692.