Insufficiently Protected Credentials vulnerability in OpenText™ AccuRev allows Authentication Bypass
Published Nov 26, 2024
9.0
CRITICALCVSS 4.0
EPSS 0.47%
Description
Insufficiently Protected Credentials vulnerability in OpenText™ AccuRev allows Authentication Bypass. When installed on a Linux or Solaris system
the vulnerability could allow anyone who knows a valid AccuRev username can use the AccuRev client to login and gain access to AccuRev source control without knowing the user’s password.
This issue affects AccuRev: 2017.1.
Affected products
-
- Version 2017.1StatusaffectedConstraints-
- Version
No data.
-
- Version 2017.1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Opentext | Accurev for Ldap Integration | unaffected |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
KM03544106 - AccuRev for LDAP Integration, version 2017.1, access may be granted without a password - CVE-2019-17082 https://support.microfocus.com/kb/kmdoc.php
References (2)
Change history (0)
No recorded changes yet.