Omnis Studio 10.22.00 has incorrect access control. It advertises a feature for making Omnis libraries "always private" - this is supposed to be an irreversible operation. However, due to implementation issues, "always private" Omnis libraries can be opened by the Omnis Studio browser by bypassing specific checks. This violates the expected behavior of an "irreversible operation".
Metrics
Affected Vendors & Products
References
History
Thu, 24 Oct 2024 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-276 | |
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: mitre
Published: 2023-07-20T00:00:00
Updated: 2024-10-24T20:28:58.255Z
Reserved: 2023-07-14T00:00:00
Link: CVE-2023-38335

Updated: 2024-08-02T17:39:12.753Z

Status : Modified
Published: 2023-07-20T18:15:12.227
Modified: 2024-11-21T08:13:21.500
Link: CVE-2023-38335

No data.