CVE-2024-56404
CVSS 3.1 Score 9.9 of 10 (high)
Details
Summary
CVE-2024-56404 is a vulnerability affecting On-Premise installations of One Identity Identity Manager 9.x before version 9.3. This issue involves an insecure direct object reference (IDOR), which can be exploited to gain unauthorized privilege escalation. By manipulating specific object references, an attacker can access data or functionality that is not intended for their level of authorization. This vulnerability can have serious consequences, potentially allowing an attacker to gain administrative control and compromise the affected system. Organizations using the impacted version of One Identity Identity Manager are urged to upgrade to a patch release as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Identity Manager
Affected Vendors
- Meru Networks