A local low-level user on the server machine with credentials to the running OAS services can create and execute a report with an rdlx file on the server system itself. Any code within the rdlx file of the report executes with SYSTEM privileges, resulting in privilege escalation.
Metrics
Affected Vendors & Products
References
History
Fri, 06 Dec 2024 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Openautomationsoftware
Openautomationsoftware oas Platform |
|
CPEs | cpe:2.3:a:openautomationsoftware:oas_platform:*:*:*:*:*:*:*:* | |
Vendors & Products |
Openautomationsoftware
Openautomationsoftware oas Platform |
|
Metrics |
ssvc
|
Fri, 06 Dec 2024 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A local low-level user on the server machine with credentials to the running OAS services can create and execute a report with an rdlx file on the server system itself. Any code within the rdlx file of the report executes with SYSTEM privileges, resulting in privilege escalation. | |
Title | Open Automation Software Incorrect Execution-Assigned Permissions | |
Weaknesses | CWE-279 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: icscert
Published: 2024-12-06T17:45:51.853Z
Updated: 2024-12-06T20:43:08.930Z
Reserved: 2024-11-14T17:19:47.353Z
Link: CVE-2024-11220
Vulnrichment
Updated: 2024-12-06T19:20:30.655Z
NVD
Status : Received
Published: 2024-12-06T18:15:22.407
Modified: 2024-12-06T18:15:22.407
Link: CVE-2024-11220
Redhat
No data.