CVE-2019-17082

CRITICAL

OpenText AccuRev 2017.1.1 - Auth Bypass

Title source: llm
STIX 2.1

Description

Insufficiently Protected Credentials vulnerability in OpenText™ AccuRev allows Authentication Bypass. When installed on a Linux or Solaris system the vulnerability could allow anyone who knows a valid AccuRev username can use the AccuRev client to login and gain access to AccuRev source control without knowing the user’s password. This issue affects AccuRev: 2017.1.

References (1)

Core 1

Scores

CVSS v4 9.0
EPSS 0.0045
EPSS Percentile 35.7%
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:N/R:I/V:C/RE:M/U:Red

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-522
Status published
Products (1)
OpenText™/AccuRev 2017.1
Published Nov 26, 2024
Tracked Since Feb 18, 2026