CVE-2025-1969

MEDIUM

TEAM <1.2.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

Improper request input validation in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center allows a user to modify a valid request and spoof an approval in TEAM. Upgrade TEAM to the latest release v.1.2.2. Follow instructions in updating TEAM documentation for updating process

Scores

CVSS v3 4.3
EPSS 0.0029
EPSS Percentile 52.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-807
Status published
Products (1)
AWS/Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center < 1.2.2
Published Mar 04, 2025
Tracked Since Feb 18, 2026