CVE-2024-4211
Severity CVSS v4.0:
LOW
Type:
Unavailable / Other
Publication date:
16/10/2024
Last modified:
21/10/2024
Description
Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allows Exploiting Incorrectly Configured Access Control Security Levels.<br />
<br />
<br />
Multiple missing permission checks - ALM job config has been discovered in OpenText Application Automation Tools. The vulnerability could allow users with Overall/Read permission to enumerate ALM server names, usernames and client IDs configured to be used with ALM servers.<br />
<br />
<br />
This issue affects OpenText Application Automation Tools: 24.1.0 and below.
Impact
Base Score 4.0
1.80
Severity 4.0
LOW
Base Score 3.x
2.40
Severity 3.x
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:microfocus:application_automation_tools:*:*:*:*:*:jenkins:*:* | 24.1.0 (including) |
To consult the complete list of CPE names with products and versions, see this page



