First published: Tue Jun 11 2024(Updated: )
A low severity vulnerability in BIPS has been identified where an attacker with high privileges or a compromised high privilege account can overwrite Read-Only smart rules via a specially crafted API request.
Credit: 13061848-ea10-403d-bd75-c83a022c2891
Affected Software | Affected Version | How to fix |
---|---|---|
BIPS BeyondInsight PasswordSafe | ||
BeyondTrust BeyondInsight Password Safe | >=23.2<23.2.0.1293 | |
BeyondTrust BeyondInsight Password Safe | >=23.3<23.3.0.959 | |
BeyondTrust BeyondInsight Password Safe | =24.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-5812 is classified as a low severity vulnerability.
CVE-2024-5812 allows an attacker with high privileges to overwrite Read-Only smart rules via a specially crafted API request.
CVE-2024-5812 affects BeyondTrust BeyondInsight PasswordSafe versions up to 23.2.0.1293, 23.3.0.959, and 24.1.
To mitigate CVE-2024-5812, ensure that only authorized users have high privilege accounts.
As of now, please consult your BeyondTrust support representative for patch availability regarding CVE-2024-5812.