Back

CRITICAL

Insufficiently Protected Credentials vulnerability in OpenText™ AccuRev allows Authentication Bypass

Published Nov 26, 2024

Description

Insufficiently Protected Credentials vulnerability in OpenText™ AccuRev allows Authentication Bypass. When installed on a Linux or Solaris system

the vulnerability could allow anyone who knows a valid AccuRev username can use the AccuRev client to login and gain access to AccuRev source control without knowing the user’s password.

This issue affects AccuRev: 2017.1.

Affected products

Remediation

Vendor solution

KM03544106 - AccuRev for LDAP Integration, version 2017.1, access may be granted without a password - CVE-2019-17082 https://support.microfocus.com/kb/kmdoc.php

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner OpenText
Published Nov 26, 2024
Updated Dec 17, 2024
Reserved Oct 2, 2019
CISA Vulnrichment
Updated Nov 26, 2024
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner OpenText
Published Nov 26, 2024
Updated Dec 17, 2024
Exploited since n/a
EUVD-2019-7550