Home

Description

Insufficiently Protected Credentials vulnerability in OpenText™ AccuRev allows Authentication Bypass. When installed on a Linux or Solaris system the vulnerability could allow anyone who knows a valid AccuRev username can use the AccuRev client to login and gain access to AccuRev source control without knowing the user’s password. This issue affects AccuRev: 2017.1.

PUBLISHED Reserved 2019-10-02 | Published 2024-11-26 | Updated 2024-12-17 | Assigner OpenText




CRITICAL: 9.0CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:P/AU:N/R:I/V:C/RE:M/U:Red

Problem types

CWE-522 Insufficiently Protected Credentials

Product status

Default status
unaffected

2017.1
affected

References

support.microfocus.com/kb/kmdoc.php?id=KM03544106

cve.org (CVE-2019-17082)

nvd.nist.gov (CVE-2019-17082)

Download JSON