HIGH🇵🇱 Wersja polska

CVE-2024-25652

CVSS 7.6v3.1pub. 2024-03-14upd. 2025-10-10

In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with access to Report functionality via UNLIMITED ADMIN MODE (with access to the Report functionality) to gain unauthorized access to remote sessions created by legitimate users through information obtained from the Custom Legacy Report functionality.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
  • Delinea Secret Server

    APP
    Delinea
    11.4.000000
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2023-4589CRITICAL9.1PL ✓same product

Delinea Secret Server — brak weryfikacji integralności pakietów aktualizacji

CVE-2024-33891HIGH8.8same product

Delinea Secret Server before 11.7.000001 allows attackers to bypass authentication via the SOAP API in SecretS...

CVE-2025-12810MEDIUM5.3same product

Podatność w ramach improper authentication w Delinea Inc. Secret Server On-Prem (moduły RPC Password Rotation)...

CVE-2024-12908MEDIUM6.9same product

Delinea addressed a reported case on Secret Server v11.7.31 (protocol handler version 6.0.3.26) where, within ...

CVE-2024-25649MEDIUM6.7same product

In Delinea PAM Secret Server 11.4, it is possible for an attacker (with Administrator access to the Secret Ser...