In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with access to Report functionality via UNLIMITED ADMIN MODE (with access to the Report functionality) to gain unauthorized access to remote sessions created by legitimate users through information obtained from the Custom Legacy Report functionality.
History

Tue, 20 May 2025 15:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-863

Fri, 09 May 2025 20:30:00 +0000

Type Values Removed Values Added
Description In Delinea PAM Secret Server 11.4, it is possible for a user (with access to the Report functionality) to gain unauthorized access to remote sessions created by legitimate users. In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with access to Report functionality via UNLIMITED ADMIN MODE (with access to the Report functionality) to gain unauthorized access to remote sessions created by legitimate users through information obtained from the Custom Legacy Report functionality.
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H'}


Thu, 01 May 2025 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Delinea
Delinea secret Server
CPEs cpe:2.3:a:delinea:secret_server:11.4:*:*:*:*:*:*:*
Vendors & Products Delinea
Delinea secret Server

Thu, 10 Apr 2025 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Delinea Pam
Delinea Pam secret Server
CPEs cpe:2.3:a:delinea_pam:secret_server:*:*:*:*:*:*:*:*
Vendors & Products Delinea Pam
Delinea Pam secret Server
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-03-14T00:00:00.000Z

Updated: 2025-05-20T14:46:12.371Z

Reserved: 2024-02-09T00:00:00.000Z

Link: CVE-2024-25652

cve-icon Vulnrichment

Updated: 2024-08-01T23:44:09.758Z

cve-icon NVD

Status : Modified

Published: 2024-03-14T03:15:08.877

Modified: 2025-05-20T15:16:03.700

Link: CVE-2024-25652

cve-icon Redhat

No data.