CVE Vulnerabilities

CVE-2017-6894

Improper Privilege Management

Published: Mar 29, 2023 | Modified: Apr 06, 2023
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability exists in FlexNet Manager Suite releases 2015 R2 SP3 and earlier (including FlexNet Manager Platform 9.2 and earlier) that affects the inventory gathering components and can be exploited by local users to perform certain actions with elevated privileges on the local system.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Flexnet_manager Flexera * 9.2 (including)
Flexnet_manager_suite_2015 Flexera - (including) - (including)
Flexnet_manager_suite_2015 Flexera r2 (including) r2 (including)
Flexnet_manager_suite_2015 Flexera r2-sp1 (including) r2-sp1 (including)
Flexnet_manager_suite_2015 Flexera r2-sp2 (including) r2-sp2 (including)
Flexnet_manager_suite_2015 Flexera r2-sp3 (including) r2-sp3 (including)

Potential Mitigations

References