CVE-2024-30299

Adobe Framemaker Publishing Server versions 2020.3, 2022.2 and earlier are affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain unauthorized access or elevated privileges within the application. Exploitation of this issue does not require user interaction.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:adobe:framemaker_publishing_server:*:*:*:*:*:*:*:*
cpe:2.3:a:adobe:framemaker_publishing_server:2020:-:*:*:*:*:*:*
cpe:2.3:a:adobe:framemaker_publishing_server:2020:update1:*:*:*:*:*:*
cpe:2.3:a:adobe:framemaker_publishing_server:2020:update2:*:*:*:*:*:*
cpe:2.3:a:adobe:framemaker_publishing_server:2020:update3:*:*:*:*:*:*
cpe:2.3:a:adobe:framemaker_publishing_server:2022:-:*:*:*:*:*:*
cpe:2.3:a:adobe:framemaker_publishing_server:2022:update1:*:*:*:*:*:*
cpe:2.3:a:adobe:framemaker_publishing_server:2022:update2:*:*:*:*:*:*

History

21 Nov 2024, 09:11

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 10.0
References () https://helpx.adobe.com/security/products/framemaker-publishing-server/apsb24-38.html - Vendor Advisory () https://helpx.adobe.com/security/products/framemaker-publishing-server/apsb24-38.html - Vendor Advisory

15 Jul 2024, 17:37

Type Values Removed Values Added
First Time Adobe
Adobe framemaker Publishing Server
CPE cpe:2.3:a:adobe:framemaker_publishing_server:2020:update2:*:*:*:*:*:*
cpe:2.3:a:adobe:framemaker_publishing_server:2022:update2:*:*:*:*:*:*
cpe:2.3:a:adobe:framemaker_publishing_server:2020:update1:*:*:*:*:*:*
cpe:2.3:a:adobe:framemaker_publishing_server:2020:update3:*:*:*:*:*:*
cpe:2.3:a:adobe:framemaker_publishing_server:*:*:*:*:*:*:*:*
cpe:2.3:a:adobe:framemaker_publishing_server:2022:-:*:*:*:*:*:*
cpe:2.3:a:adobe:framemaker_publishing_server:2022:update1:*:*:*:*:*:*
cpe:2.3:a:adobe:framemaker_publishing_server:2020:-:*:*:*:*:*:*
References () https://helpx.adobe.com/security/products/framemaker-publishing-server/apsb24-38.html - () https://helpx.adobe.com/security/products/framemaker-publishing-server/apsb24-38.html - Vendor Advisory
CVSS v2 : unknown
v3 : 10.0
v2 : unknown
v3 : 9.8

13 Jun 2024, 18:35

Type Values Removed Values Added
Summary
  • (es) Las versiones 2020.3, 2022.2 y anteriores de Adobe Framemaker Publishing Server se ven afectadas por una vulnerabilidad de autenticación incorrecta que podría provocar una escalada de privilegios. Un atacante podría aprovechar esta vulnerabilidad para obtener acceso no autorizado o privilegios elevados dentro de la aplicación. La explotación de este problema no requiere la interacción del usuario.

13 Jun 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-13 12:15

Updated : 2024-11-21 09:11


NVD link : CVE-2024-30299

Mitre link : CVE-2024-30299

CVE.ORG link : CVE-2024-30299


JSON object : View

Products Affected

adobe

  • framemaker_publishing_server
CWE
CWE-287

Improper Authentication