CVE Vulnerabilities

CVE-2023-25074

Published: Jul 25, 2023 | Modified: Aug 01, 2023
CVSS 3.x
5.4
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Improper privilege validation in Command Centre Server allows authenticated unprivileged operators to modify and view Competencies.

This issue affects Command Centre: vEL8.90 prior to vEL8.90.1318 (MR1), vEL8.80 prior to vEL8.80.1192 (MR2), vEL8.70 prior to vEL8.70.2185 (MR4),

vEL8.60 prior to vEL8.60.2347 (MR6),

vEL8.50 prior to vEL8.50.2831 (MR8), all versions vEL8.40 and prior.

Affected Software

Name Vendor Start Version End Version
Command_centre Gallagher * 8.40.2216 (including)
Command_centre Gallagher 8.50 (including) 8.50.2831 (excluding)
Command_centre Gallagher 8.60 (including) 8.60.2347 (excluding)
Command_centre Gallagher 8.70 (including) 8.70.2185 (excluding)
Command_centre Gallagher 8.80 (including) 8.80.1192 (excluding)
Command_centre Gallagher 8.90 (including) 8.90.1318 (excluding)

References