Description
IBM Global Configuration Management 7.0.2 and 7.0.3 could allow an authenticated user to archive a global baseline due to improper access controls.
Published: 2024-08-20
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-39185 IBM Global Configuration Management 7.0.2 and 7.0.3 could allow an authenticated user to archive a global baseline due to improper access controls.
History

Mon, 26 Aug 2024 19:00:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-Other

Wed, 21 Aug 2024 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 20 Aug 2024 19:30:00 +0000

Type Values Removed Values Added
Description IBM Global Configuration Management 7.0.2 and 7.0.3 could allow an authenticated user to archive a global baseline due to improper access controls.
Title IBM Global Configuration Management incorrect ownership assignment
First Time appeared Ibm
Ibm global Configuration Management
Weaknesses CWE-708
CPEs cpe:2.3:a:ibm:global_configuration_management:7.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:global_configuration_management:7.0.3:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm global Configuration Management
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Ibm Global Configuration Management
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2024-08-21T19:42:23.455Z

Reserved: 2024-07-22T12:02:59.129Z

Link: CVE-2024-41773

cve-icon Vulnrichment

Updated: 2024-08-21T19:42:18.674Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-20T20:15:08.423

Modified: 2024-08-26T18:33:07.997

Link: CVE-2024-41773

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses