PT-2025-3275 · One Identity · One Identity Identity Manager

CVE-2024-56404

·

Published

2024-12-20

·

Updated

2025-02-05

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions One Identity Identity Manager versions prior to 9.3
Description An insecure direct object reference (IDOR) issue allows privilege escalation. Only On-Premise installations are affected. The vulnerability can be exploited by a remote attacker to elevate their privileges, potentially bypassing authentication through supposedly immutable data.
Recommendations One Identity Identity Manager versions prior to 9.3: Update to version 9.3 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of the system to minimize the risk of exploitation until the update is applied.

Fix

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-01232
CVE-2024-56404

Affected Products

One Identity Identity Manager