Omnis Studio 10.22.00 has incorrect access control. It advertises an irreversible feature for locking classes within Omnis libraries: it should be no longer possible to delete, view, change, copy, rename, duplicate, or print a locked class. Due to implementation issues, locked classes in Omnis libraries can be unlocked, and thus further analyzed and modified by Omnis Studio. This allows for further analyzing and also deleting, viewing, changing, copying, renaming, duplicating, or printing previously locked Omnis classes. This violates the expected behavior of an "irreversible operation."
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/173696/Omnis-Studio-10.22.00-Library-Unlock.html | Exploit Third Party Advisory VDB Entry |
http://seclists.org/fulldisclosure/2023/Jul/42 | Exploit Mailing List Third Party Advisory |
http://seclists.org/fulldisclosure/2023/Jul/43 | Not Applicable |
https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2023-006.txt | Third Party Advisory |
Configurations
History
24 Oct 2024, 21:35
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-276 |
31 Jul 2023, 18:42
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) http://packetstormsecurity.com/files/173696/Omnis-Studio-10.22.00-Library-Unlock.html - Exploit, Third Party Advisory, VDB Entry | |
References | (FULLDISC) http://seclists.org/fulldisclosure/2023/Jul/42 - Exploit, Mailing List, Third Party Advisory | |
References | (MISC) https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2023-006.txt - Third Party Advisory | |
References | (FULLDISC) http://seclists.org/fulldisclosure/2023/Jul/43 - Not Applicable | |
CPE | cpe:2.3:a:omnis:studio:10.22.00:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
CWE | NVD-CWE-Other | |
First Time |
Omnis studio
Omnis |
26 Jul 2023, 07:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
24 Jul 2023, 16:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
21 Jul 2023, 17:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
20 Jul 2023, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-07-20 18:15
Updated : 2024-10-24 21:35
NVD link : CVE-2023-38334
Mitre link : CVE-2023-38334
CVE.ORG link : CVE-2023-38334
JSON object : View
Products Affected
omnis
- studio
CWE