There is an insufficient input validation vulnerability in
the Warehouse component of Absolute Secure Access prior to 13.06. Attackers
with system administrator permissions can impair the availability of certain
elements of the Secure Access administrative UI by writing invalid data to the
warehouse over the network. There is no loss of warehouse integrity or
confidentiality, the security scope is unchanged. Loss of availability is high.
References
Link | Resource |
---|---|
https://www.absolute.com/platform/security-information/vulnerability-archive/secure-access-1306/cve-2024-37346/ | Vendor Advisory |
Configurations
History
07 Aug 2024, 16:47
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-noinfo | |
References | () https://www.absolute.com/platform/security-information/vulnerability-archive/secure-access-1306/cve-2024-37346/ - Vendor Advisory | |
First Time |
Absolute
Absolute secure Access |
|
Summary |
|
|
CPE | cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:* |
20 Jun 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-06-20 17:15
Updated : 2024-08-07 16:47
NVD link : CVE-2024-37346
Mitre link : CVE-2024-37346
CVE.ORG link : CVE-2024-37346
JSON object : View
Products Affected
absolute
- secure_access
CWE