CVE-2021-28488

Ericsson Network Manager (ENM) before 21.2 has incorrect access-control behavior (that only affects the level of access available to persons who were already granted a highly privileged role). Users in the same AMOS authorization group can retrieve managed-network data that was not set to be accessible to the entire group (i.e., was only set to be accessible to a subset of that group).
Configurations

Configuration 1 (hide)

cpe:2.3:a:ericsson:network_manager:*:*:*:*:*:*:*:*

History

12 Jul 2022, 17:42

Type Values Removed Values Added
CWE CWE-269 CWE-668

24 Mar 2022, 15:26

Type Values Removed Values Added
CWE CWE-732 CWE-269

20 Mar 2022, 03:15

Type Values Removed Values Added
Summary Ericsson Network Manager (ENM) before 21.2 has incorrect access-control behavior (that only affects the level of access available to persons who were already granted a highly privileged role). Users in the same AMOS authorization group can retrieve managed-network that was not set to be accessible to the entire group (i.e., was only set to be accessible to a subset of that group). Ericsson Network Manager (ENM) before 21.2 has incorrect access-control behavior (that only affects the level of access available to persons who were already granted a highly privileged role). Users in the same AMOS authorization group can retrieve managed-network data that was not set to be accessible to the entire group (i.e., was only set to be accessible to a subset of that group).

13 Mar 2022, 19:15

Type Values Removed Values Added
Summary Ericsson Network Manager 20.2 has Insecure Permissions. Ericsson Network Manager (ENM) before 21.2 has incorrect access-control behavior (that only affects the level of access available to persons who were already granted a highly privileged role). Users in the same AMOS authorization group can retrieve managed-network that was not set to be accessible to the entire group (i.e., was only set to be accessible to a subset of that group).

12 Mar 2022, 04:02

Type Values Removed Values Added
References (MISC) https://www.ericsson.com - (MISC) https://www.ericsson.com - Vendor Advisory
References (MISC) https://www.gruppotim.it/it/footer/red-team.html - (MISC) https://www.gruppotim.it/it/footer/red-team.html - Third Party Advisory
References (MISC) https://www.ericsson.com/en/about-us/enterprise-security/psirt - (MISC) https://www.ericsson.com/en/about-us/enterprise-security/psirt - Vendor Advisory
CPE cpe:2.3:a:ericsson:network_manager:*:*:*:*:*:*:*:*
First Time Ericsson network Manager
Ericsson
CWE CWE-732
CVSS v2 : unknown
v3 : unknown
v2 : 4.0
v3 : 6.5

10 Mar 2022, 17:55

Type Values Removed Values Added
New CVE

Information

Published : 2022-03-10 17:42

Updated : 2023-12-10 14:22


NVD link : CVE-2021-28488

Mitre link : CVE-2021-28488

CVE.ORG link : CVE-2021-28488


JSON object : View

Products Affected

ericsson

  • network_manager
CWE
CWE-668

Exposure of Resource to Wrong Sphere