VYPR
Unrated severityNVD Advisory· Published Aug 21, 2024· Updated Aug 21, 2024

Improper handling of token allows access to restricted resource in Privileged Access Manager

CVE-2020-11846

Description

A vulnerability found in OpenText Privileged Access Manager that issues a token. on successful issuance of the token, a cookie gets set that allows unrestricted access to all the application resources. This issue affects Privileged Access Manager before 3.7.0.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

OpenText Privileged Access Manager before 3.7.0.1 sets a cookie on token issuance that allows unrestricted access to all application resources.

Vulnerability

A vulnerability in OpenText Privileged Access Manager (formerly NetIQ Privileged Account Manager) before version 3.7.0.1 [1] allows unrestricted access to all application resources after a token is issued. The issue occurs because a cookie is set upon successful token issuance that does not properly restrict access, enabling any user with the cookie to access resources without further authorization.

Exploitation

An attacker who can obtain a valid token (and the associated cookie) from the application — for example, by authenticating legitimately or intercepting a token issuance — can then use that cookie to access any application resource. No additional authentication or authorization checks are performed for subsequent requests.

Impact

Successful exploitation allows an attacker with a valid token cookie to access all application resources without restriction. This can lead to unauthorized access to sensitive data, administrative functions, and other protected areas of the application, resulting in a complete compromise of confidentiality, integrity, and availability of the affected system.

Mitigation

The vulnerability is fixed in Privileged Access Manager version 3.7.0.1, released in June 2020 [1]. Users should upgrade to this patched version immediately. No workarounds have been publicly disclosed in the available references.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.