CVE-2024-20738

Adobe FrameMaker Publishing Server versions 2022.1 and earlier are affected by an Improper Authentication vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass authentication mechanisms and gain unauthorized access. Exploitation of this issue does not require user interaction.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:adobe:framemaker_publishing_server:*:*:*:*:*:*:*:*
cpe:2.3:a:adobe:framemaker_publishing_server:2022:-:*:*:*:*:*:*
cpe:2.3:a:adobe:framemaker_publishing_server:2022:update1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

15 Mar 2024, 17:15

Type Values Removed Values Added
Summary (en) Adobe Framemaker versions 2022.1 and earlier are affected by an Improper Authentication vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass authentication mechanisms and gain unauthorized access. Exploitation of this issue does not require user interaction. (en) Adobe FrameMaker Publishing Server versions 2022.1 and earlier are affected by an Improper Authentication vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass authentication mechanisms and gain unauthorized access. Exploitation of this issue does not require user interaction.

12 Mar 2024, 14:54

Type Values Removed Values Added
CPE cpe:2.3:a:adobe:framemaker_publishing_server:2022:update1:*:*:*:*:*:*
cpe:2.3:a:adobe:framemaker_publishing_server:2022:-:*:*:*:*:*:*
cpe:2.3:a:adobe:framemaker_publishing_server:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
References () https://helpx.adobe.com/security/products/framemaker-publishing-server/apsb24-10.html - () https://helpx.adobe.com/security/products/framemaker-publishing-server/apsb24-10.html - Patch, Vendor Advisory
Summary
  • (es) Las versiones 2022.1 y anteriores de Adobe Framemaker se ven afectadas por una vulnerabilidad de autenticación incorrecta que podría provocar la omisión de una función de seguridad. Un atacante podría aprovechar esta vulnerabilidad para eludir los mecanismos de autenticación y obtener acceso no autorizado. La explotación de este problema no requiere la interacción del usuario.
First Time Adobe framemaker Publishing Server
Microsoft windows
Adobe
Microsoft

15 Feb 2024, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-15 13:15

Updated : 2024-03-15 17:15


NVD link : CVE-2024-20738

Mitre link : CVE-2024-20738

CVE.ORG link : CVE-2024-20738


JSON object : View

Products Affected

microsoft

  • windows

adobe

  • framemaker_publishing_server
CWE
CWE-287

Improper Authentication