CVE-2025-1969: Request approval spoofing in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center
Improper request input validation in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center allows a user to modify a valid request and spoof an approval in TEAM.
Upgrade TEAM to the latest release v.1.2.2. Follow instructions in updating TEAM documentation for updating process
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1969?
CVE-2025-1969 has a medium severity level due to improper request input validation that could lead to spoofing approvals.
How do I fix CVE-2025-1969?
To fix CVE-2025-1969, you should upgrade AWS Temporary Elevated Access Management to version 1.2.2.
What does CVE-2025-1969 affect?
CVE-2025-1969 affects AWS Temporary Elevated Access Management software versions prior to 1.2.2.
What is the primary vulnerability in CVE-2025-1969?
The primary vulnerability in CVE-2025-1969 is improper request input validation that allows for approval spoofing.
What are the potential consequences of CVE-2025-1969?
The potential consequences of CVE-2025-1969 include unauthorized approvals which could compromise security in AWS IAM Identity Center.