← Back

CVE-2024-25652

nvd nist
Published: Mar 14, 2024Modified: Jun 17, 2026

JSON object

Loading...
8.4
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Exploitability: 1.7 / Impact: 6.0
Source: NVD

Description

In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with access to Report functionality via UNLIMITED ADMIN MODE (with access to the Report functionality) to gain unauthorized access to remote sessions created by legitimate users through information obtained from the Custom Legacy Report functionality.

Affected (1)

1 product
Secret Server
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 11.4.000000

References (5)

Source: 1443cd92-d354-46d2-9290-d812316ca43a
Vendor Advisory
Source: 1443cd92-d354-46d2-9290-d812316ca43a
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.