CVE-2024-12799 Details
Description
Insufficiently Protected Credentials vulnerability in OpenText Identity Manager Advanced Edition on Windows, Linux, 64 bit allows Privilege Abuse. This vulnerability could allow an authenticated user to obtain higher privileged user’s sensitive information via crafted payload. This issue affects Identity Manager Advanced Edition: from 4.8.0.0 through 4.8.7.0102, 4.9.0.0.
A vulnerability allowing insufficiently protected credentials has been identified in OpenText Identity Manager Advanced Edition versions 4.8.0.0 through 4.8.7.0102 and 4.9.0.0 on Windows and Linux (64-bit). This vulnerability could enable an authenticated user to access sensitive information of higher privileged users through crafted payloads, facilitating privilege abuse.
To address this vulnerability, users can stop the Tomcat service running Identity Applications, back up the UIRegistry.jar file, and then replace it with a patched version. Instructions for applying the patch vary depending on the specific version of Identity Manager in use.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 5, 2025CISA-ADP
Assessed Mar 5, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://portal.microfocus.com/s/article/KM000037455 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-522 | Insufficiently Protected Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| OpenText Identity Manager Advanced Edition | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 5, 2025 | New CVE Received | [email protected] |
Volerion