CVE-2024-33891
EUVD-2024-3159528.04.2024, 23:15
Delinea Secret Server before 11.7.000001 allows attackers to bypass authentication via the SOAP API in SecretServer/webservices/SSWebService.asmx. This is related to a hardcoded key, the use of the integer 2 for the Admin user, and removal of the oauthExpirationId attribute.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| delinea | secret_server | 𝑥 < 11.7.000001 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References