In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with access to Report functionality via UNLIMITED ADMIN MODE (with access to the Report functionality) to gain unauthorized access to remote sessions created by legitimate users through information obtained from the Custom Legacy Report functionality.
oryginał ENCVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:HDelinea Secret Server
APPDelinea11.4.000000
Powiązane podatności
Delinea Secret Server — brak weryfikacji integralności pakietów aktualizacji
Delinea Secret Server before 11.7.000001 allows attackers to bypass authentication via the SOAP API in SecretS...
Podatność w ramach improper authentication w Delinea Inc. Secret Server On-Prem (moduły RPC Password Rotation)...
Delinea addressed a reported case on Secret Server v11.7.31 (protocol handler version 6.0.3.26) where, within ...
In Delinea PAM Secret Server 11.4, it is possible for an attacker (with Administrator access to the Secret Ser...