CVE-2023-44324

Adobe FrameMaker Publishing Server versions 2022 and earlier are affected by an Improper Authentication vulnerability that could result in a Security feature bypass. An unauthenticated attacker can abuse this vulnerability to access the API and leak default admin's password. Exploitation of this issue does not require user interaction.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:adobe:framemaker_publishing_server:*:*:*:*:*:*:*:*
cpe:2.3:a:adobe:framemaker_publishing_server:2022:-:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

15 Mar 2024, 10:15

Type Values Removed Values Added
Summary (en) Adobe FrameMaker versions 2022 and earlier are affected by an Improper Authentication vulnerability that could result in a Security feature bypass. An unauthenticated attacker can abuse this vulnerability to access the API and leak default admin's password. Exploitation of this issue does not require user interaction. (en) Adobe FrameMaker Publishing Server versions 2022 and earlier are affected by an Improper Authentication vulnerability that could result in a Security feature bypass. An unauthenticated attacker can abuse this vulnerability to access the API and leak default admin's password. Exploitation of this issue does not require user interaction.

05 Mar 2024, 19:56

Type Values Removed Values Added
CPE cpe:2.3:a:adobe:framemaker:*:*:*:*:*:*:*:* cpe:2.3:a:adobe:framemaker_publishing_server:2022:-:*:*:*:*:*:*
cpe:2.3:a:adobe:framemaker_publishing_server:*:*:*:*:*:*:*:*
First Time Adobe framemaker Publishing Server
References () https://helpx.adobe.com/security/products/framemaker-publishing-server/apsb23-58.html - () https://helpx.adobe.com/security/products/framemaker-publishing-server/apsb23-58.html - Vendor Advisory

06 Feb 2024, 13:15

Type Values Removed Values Added
References
  • {'url': 'https://helpx.adobe.com/security/products/framemaker/apsb23-58.html', 'tags': ['Release Notes', 'Vendor Advisory'], 'source': 'psirt@adobe.com'}
  • () https://helpx.adobe.com/security/products/framemaker-publishing-server/apsb23-58.html -

23 Nov 2023, 03:39

Type Values Removed Values Added
References () https://helpx.adobe.com/security/products/framemaker/apsb23-58.html - () https://helpx.adobe.com/security/products/framemaker/apsb23-58.html - Release Notes, Vendor Advisory
First Time Adobe framemaker
Adobe
Microsoft windows
Microsoft
CPE cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:adobe:framemaker:*:*:*:*:*:*:*:*

17 Nov 2023, 13:58

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-17 13:15

Updated : 2024-03-15 10:15


NVD link : CVE-2023-44324

Mitre link : CVE-2023-44324

CVE.ORG link : CVE-2023-44324


JSON object : View

Products Affected

adobe

  • framemaker_publishing_server

microsoft

  • windows
CWE
CWE-287

Improper Authentication