CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-4332

CVSS 9.3v4.0pub. 2024-06-03upd. 2026-04-15

An authentication bypass vulnerability has been identified in the REST and SOAP API components of Tripwire Enterprise (TE) 9.1.0 when TE is configured to use LDAP/Active Directory SAML authentication and its optional "Auto-synchronize LDAP Users, Roles, and Groups" feature is enabled. This vulnerability allows unauthenticated attackers to bypass authentication if a valid username is known. Exploitation of this vulnerability could allow remote attackers to gain privileged access to the APIs and lead to unauthorized information disclosure or modification.

🤖 AI Analysis
How it works

The vulnerability results from improper implementation of the authentication mechanism (CWE-303, CWE-306) in the REST and SOAP API components of Tripwire Enterprise. When the 'Auto-synchronize LDAP Users, Roles, and Groups' feature is enabled, user identity verification in the SAML/LDAP flow is performed incorrectly, allowing it to be bypassed. It is sufficient that the attacker knows a valid user account name — no other form of authentication is required.

Impact

A remote unauthenticated attacker can gain privileged access to Tripwire Enterprise API interfaces, which may lead to unauthorized reading or modification of configuration data and monitoring managed by the system.

Mitigation & patch

Apply patches available from the vendor according to the references (Fortra security advisory FI-2024-006: https://www.fortra.com/security/advisory/fi-2024-006). Until the fix is implemented, consider disabling the 'Auto-synchronize LDAP Users, Roles, and Groups' feature or restricting network access to REST and SOAP API interfaces only to trusted hosts.

Who is affected

Tripwire Enterprise (TE) version 9.1.0, configured with LDAP/Active Directory SAML authentication and the 'Auto-synchronize LDAP Users, Roles, and Groups' option enabled

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:C/RE:L/U:Red
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Auth Bypass
CWE
References