VulnerabilityDeferred
CVE-2024-45488
One Identity Safeguard for Privileged Passwords before 7.5.2 allows unauthorized access because of an issue related to cookies.
CRITICAL 9.8EPSS 50.6%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 50.6%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
One Identity Safeguard for Privileged Passwords before 7.5.2 allows unauthorized access because of an issue related to cookies. This only affects virtual appliance installations (VMware or HyperV). The fixed versions are 7.0.5.1 LTS, 7.4.2, and 7.5.2.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 50.60% probability · 99th percentile
- CISA KEV
- Not listed
- Source
- cve@mitre.org
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.