CVE-2023-4501
OpenText Visual COBOL, COBOL Server, Enterprise Developer, Enterprise Server, visual_cobal_cobal_server_enterprise_developer_enterprise_server, cobol server
User authentication with username and password credentials is ineffective in OpenText (Micro Focus) Visual COBOL, COBOL Server, Enterprise Developer, and Enterprise Server (including product variants such as Enterprise Test Server), versions 7.0 patch updates 19 and 20, 8.0 patch updates 8 and 9, and 9.0 patch update 1, when LDAP-based authentication is used with certain configurations. When the vulnerability is active, authentication succeeds with any valid username, regardless of whether the password is correct; it may also succeed with an invalid username (and any password). This allows...
- CVSS
- 9.8
- EPSS
- 0.62% 46.4% percentile
- CISA KEV
- Not listed
- Published
- 2023.09.13