CVE-2018-1000634

T

he Open Microscopy Environment OMERO.server version 5.4.0 to 5.4.6 contains an Improper Access Control vulnerability in User management that can result in administrative user with privilege restrictions logging in as a more powerful administrator. This attack appear to be exploitable via Use user administration privilege to set the password of a more powerful administrator. This vulnerability appears to have been fixed in 5.4.7.

Configurations

Configuration 1 (hide)

cpe:2.3:a:openmicroscopy:omero:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:40

Type Values Removed Values Added
References () https://www.openmicroscopy.org/2018/07/26/omero-5-4-7.html - Patch, Vendor Advisory () https://www.openmicroscopy.org/2018/07/26/omero-5-4-7.html - Patch, Vendor Advisory
References () https://www.openmicroscopy.org/security/advisories/2018-SV3-modify-user-password/ - Vendor Advisory () https://www.openmicroscopy.org/security/advisories/2018-SV3-modify-user-password/ - Vendor Advisory

Information

Published : 2018-08-20 19:31

Updated : 2024-11-21 03:40


NVD link : CVE-2018-1000634

Mitre link : CVE-2018-1000634

CVE.ORG link : CVE-2018-1000634


JSON object : View

Products Affected
CWE
CWE-269

Improper Privilege Management