Broken Access Control leading to SSRF in NetIQ Identity Console
Vulnerability Description
An improper authorization level has been detected in the login panel. It may lead to unauthenticated Server Side Request Forgery and allows to perform open services enumeration. Server makes query to provided server (Server IP/DNS field) and is triggering connection to arbitrary address.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-7240
Credits & Attribution
No credits recorded in the NVD database.
More from OpenText
View All →Affected Vendor
OpenText
View all reports →