« Volver al listado

CVE-2023-7248

Estado: ModificadaCrítica (9.8)—

Certain functionality in OpenText Vertica Management console might be prone to bypass via crafted requests.

The vulnerability would affect one of Vertica’s authentication functionalities by allowing specially crafted requests and sequences. This issue impacts the following Vertica Management Console versions: 10.x 11.1.1-24 or lower 12.0.4-18 or lower

Please upgrade to one of the following Vertica Management Console versions: 10.x to upgrade to latest versions from below. 11.1.1-25 12.0.4-19 23.x 24.x

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-7248",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-7248",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-03-18T14:06:10.703241Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@opentext.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 1.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@opentext.com",
      "affectedData": [
        {
          "vendor": "Opentext",
          "product": "Vertica Management Console",
          "versions": [
            {
              "status": "affected",
              "version": "10.x"
            },
            {
              "status": "affected",
              "version": "11.x",
              "versionType": "custom",
              "lessThanOrEqual": "11.1.1-24"
            },
            {
              "status": "affected",
              "version": "12.x",
              "versionType": "custom",
              "lessThanOrEqual": "12.0.4-18"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:opentext:vertica_management_console:10.0:*:*:*:*:*:*:*"
          ],
          "vendor": "opentext",
          "product": "vertica_management_console",
          "versions": [
            {
              "status": "affected",
              "version": "10.0",
              "lessThan": "11.0",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:opentext:vertica_management_console:11.0:*:*:*:*:*:*:*"
          ],
          "vendor": "opentext",
          "product": "vertica_management_console",
          "versions": [
            {
              "status": "affected",
              "version": "11.0",
              "versionType": "custom",
              "lessThanOrEqual": "11.1.1-24"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:opentext:vertica_management_console:12.0:*:*:*:*:*:*:*"
          ],
          "vendor": "opentext",
          "product": "vertica_management_console",
          "versions": [
            {
              "status": "affected",
              "version": "12.0",
              "versionType": "custom",
              "lessThanOrEqual": "12.0.4-18"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-03-15T20:15:07.280",
  "references": [
    {
      "url": "https://portal.microfocus.com/s/article/KM000027542?language=en_US",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@opentext.com"
    },
    {
      "url": "https://portal.microfocus.com/s/article/KM000027542?language=en_US",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@opentext.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "\nCertain functionality in OpenText Vertica Management console might be prone to bypass via crafted requests. \n\nThe vulnerability would affect one of Vertica’s authentication functionalities by allowing specially crafted requests and sequences. \nThis issue impacts the following Vertica Management Console versions:\n10.x\n11.1.1-24 or lower\n12.0.4-18 or lower\n\nPlease upgrade to one of the following Vertica Management Console versions:\n10.x to upgrade to latest versions from below.\n11.1.1-25\n12.0.4-19\n23.x\n24.x\n\n"
    },
    {
      "lang": "es",
      "value": "Ciertas funciones en la consola de OpenText Vertica Management pueden ser propensas a omitirse mediante solicitudes manipuladas. La vulnerabilidad afectaría una de las funcionalidades de autenticación de Vertica al permitir solicitudes y secuencias especialmente manipuladas. Este problema afecta las siguientes versiones de Vertica Management Console: 10.x 11.1.1-24 o anterior 12.0.4-18 o anterior Actualice a una de las siguientes versiones de Vertica Management Console: 10.x para actualizar a las últimas versiones desde abajo. 11.1.1-25 12.0.4-19 23.x 24.x"
    }
  ],
  "lastModified": "2026-06-17T06:52:24.393",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:opentext:vertica:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "056D6A40-95C6-4FEA-91C9-B5C41AE254C4",
              "versionEndIncluding": "10.1.1-26",
              "versionStartIncluding": "10.0.0-0"
            },
            {
              "criteria": "cpe:2.3:a:opentext:vertica:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C15386AE-A142-4A50-9B64-276C2FC3E959",
              "versionEndExcluding": "11.1.1-25",
              "versionStartIncluding": "11.0.0-0"
            },
            {
              "criteria": "cpe:2.3:a:opentext:vertica:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "84FC2248-AAC2-4994-BBB3-6705EAB9934B",
              "versionEndExcluding": "12.0.4-19",
              "versionStartIncluding": "12.0.0-0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@opentext.com"
}