In RSA NetWitness (NW) Platform before 12.5.1, even when an administrator revokes the access of a specific user with an active session, an internal threat actor could impersonate the revoked user and gain unauthorized access to sensitive data.
References
Configurations
No configuration.
History
21 Nov 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-276 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
18 Nov 2024, 17:11
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
18 Nov 2024, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-11-18 15:15
Updated : 2024-11-21 17:15
NVD link : CVE-2024-28058
Mitre link : CVE-2024-28058
CVE.ORG link : CVE-2024-28058
JSON object : View
Products Affected
No product.
CWE
CWE-276
Incorrect Default Permissions