CVE-2023-36496

high ForgeRock
CVSS v3 Base Score
7.7
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:L
Attack Characteristics
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Confidentiality
Low
Integrity
High
Availability
Low
Published: February 1, 2024 (832 days ago)
Last Modified: November 21, 2024
Vendor: ForgeRock
Source: NVD

Description

Delegated Admin Privilege virtual attribute provider plugin, when enabled, allows an authenticated user to elevate their permissions in the Directory Server.

References