CVE-2024-54038

Adobe Connect versions 12.6, 11.4.7 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and have a low impact on confidentiality. Exploitation of this issue does not require user interaction.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:adobe:connect:*:*:*:*:*:*:*:*
cpe:2.3:a:adobe:connect:*:*:*:*:*:*:*:*

History

07 Jan 2025, 19:15

Type Values Removed Values Added
Summary (en) Adobe Connect versions 12.6, 11.4.7 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction. (en) Adobe Connect versions 12.6, 11.4.7 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and have a low impact on confidentiality. Exploitation of this issue does not require user interaction.

19 Dec 2024, 18:58

Type Values Removed Values Added
CWE NVD-CWE-noinfo
Summary
  • (es) Las versiones 12.6, 11.4.7 y anteriores de Adobe Connect se ven afectadas por una vulnerabilidad de control de acceso inadecuado que podría provocar la omisión de una función de seguridad. Un atacante podría aprovechar esta vulnerabilidad para eludir las medidas de seguridad y obtener acceso no autorizado. La explotación de este problema no requiere la interacción del usuario.
First Time Adobe
Adobe connect
References () https://helpx.adobe.com/security/products/connect/apsb24-99.html - () https://helpx.adobe.com/security/products/connect/apsb24-99.html - Vendor Advisory
CPE cpe:2.3:a:adobe:connect:*:*:*:*:*:*:*:*

10 Dec 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-10 21:15

Updated : 2025-01-15 17:39


NVD link : CVE-2024-54038

Mitre link : CVE-2024-54038

CVE.ORG link : CVE-2024-54038


JSON object : View

Products Affected

adobe

  • connect
CWE
CWE-284

Improper Access Control

NVD-CWE-noinfo