Back to overview

CVE-2024-12799

CRITICAL
10.0
CVSS 4.0
Description
Insufficiently Protected Credentials vulnerability in OpenText Identity Manager Advanced Edition on Windows, Linux, 64 bit allows Privilege Abuse. This vulnerability could allow an authenticated user to obtain higher privileged user’s sensitive information via crafted payload. This issue affects Identity Manager Advanced Edition: from 4.8.0.0 through 4.8.7.0102, 4.9.0.0.

Metadata

CVE ID
CVE-2024-12799
State
PUBLISHED
Assigner
OpenText
Reserved
2024-12-19 15:22 UTC
Published
2025-03-05 14:55 UTC
Last updated
2025-03-05 16:21 UTC
Primary CWE
CWE-522
CWE-522 Insufficiently Protected Credentials
Vendor / Product
OpenText / Identity Manager Advanced Edition
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:P/AU:Y/R:U/V:C/RE:H/U:Red
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
OpenText Identity Manager Advanced Edition Windows,Linux,64 bit 4.8.0.0 ≤ 4.8.7.0102, 4.9.0.0
Weakness (CWE)
CWESourceDescription
CWE-522 cna CWE-522 Insufficiently Protected Credentials
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:P/AU:Y/R:U/V:C/RE:H/U:Red
Back to overview