Vulnerability Description
Insecure Permissions in Atos Eviden IDRA and IDCA before 2.7.0. A highly trusted role (Config Admin) could exceed their configuration privileges in a multi-partition environment and access some confidential data. Data integrity and availability is not at risk.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://eviden.com/solutions/digital-security/digital-identity/
- https://support.bull.com/ols/product/security/psirt/security-bulletins/potential
FAQ
What is CVE-2024-39328?
CVE-2024-39328 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Insecure Permissions in Atos Eviden IDRA and IDCA before 2.7.0. A highly trusted role (Config Admin) could exceed their configuration privileges in a multi-partition environment and access some confid...
How severe is CVE-2024-39328?
CVE-2024-39328 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-39328?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.