HIGH🇬🇧 English

CVE-2024-25652

CVSS 7.6v3.1pub. 2024-03-14upd. 2025-10-10

In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with access to Report functionality via UNLIMITED ADMIN MODE (with access to the Report functionality) to gain unauthorized access to remote sessions created by legitimate users through information obtained from the Custom Legacy Report functionality.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
  • Delinea Secret Server

    APP
    Delinea
    11.4.000000
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
Auth Bypass
CWE
Referencje

Powiązane podatności

CVE-2023-4589CRITICAL9.1PL ✓ten sam produkt

Delinea Secret Server — brak weryfikacji integralności pakietów aktualizacji

CVE-2024-33891HIGH8.8ten sam produkt

Delinea Secret Server before 11.7.000001 allows attackers to bypass authentication via the SOAP API in SecretS...

CVE-2025-12810MEDIUM5.3ten sam produkt

Podatność w ramach improper authentication w Delinea Inc. Secret Server On-Prem (moduły RPC Password Rotation)...

CVE-2024-12908MEDIUM6.9ten sam produkt

Delinea addressed a reported case on Secret Server v11.7.31 (protocol handler version 6.0.3.26) where, within ...

CVE-2024-25649MEDIUM6.7ten sam produkt

In Delinea PAM Secret Server 11.4, it is possible for an attacker (with Administrator access to the Secret Ser...