Description
Red Hat 3scale (aka RH-3scale) API Management Platform (AMP) before 2.0.0 would permit creation of an access token without a client secret. An attacker could use this flaw to circumvent authentication controls and gain access to restricted APIs. NOTE: some sources have a typo in which CVE-2017-7512 maps to an OpenVPN vulnerability. The proper CVE ID for that OpenVPN vulnerability is CVE-2017-7521. Specifically, CVE-2017-7521 is the correct CVE ID for TWO closely related findings in OpenVPN. Any source that lists BOTH CVE-2017-7512 and CVE-2017-7521 for OpenVPN should have listed ONLY CVE-2017-7521.
Published: 2017-07-07
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2017-16529 Red Hat 3scale (aka RH-3scale) API Management Platform (AMP) before 2.0.0 would permit creation of an access token without a client secret. An attacker could use this flaw to circumvent authentication controls and gain access to restricted APIs. NOTE: some sources have a typo in which CVE-2017-7512 maps to an OpenVPN vulnerability. The proper CVE ID for that OpenVPN vulnerability is CVE-2017-7521. Specifically, CVE-2017-7521 is the correct CVE ID for TWO closely related findings in OpenVPN. Any source that lists BOTH CVE-2017-7512 and CVE-2017-7521 for OpenVPN should have listed ONLY CVE-2017-7521.
History

Fri, 22 Nov 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat 3scale Amp
CPEs cpe:/a:redhat:3scale_amp:2
Vendors & Products Redhat 3scale Amp

Subscriptions

Redhat 3scale Amp 3scale Api Management Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-05T16:04:11.853Z

Reserved: 2017-04-05T00:00:00.000Z

Link: CVE-2017-7512

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2017-07-07T22:29:00.177

Modified: 2026-05-13T00:24:29.033

Link: CVE-2017-7512

cve-icon Redhat

Severity : Important

Publid Date: 2017-07-06T00:00:00Z

Links: CVE-2017-7512 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses