Secure Access 13.52
Important: Medium Severity Vulnerability Addressed in Secure Access 13.52 Server
There is a cross-site scripting vulnerability in the management console of Absolute Secure Access prior to version 13.52. Attackers with system administrator permissions can interfere with another system administrator’s use of the management console when the second administrator logs in.
The CVSS v4.0 score for this vulnerability is 5.9, Medium.
Attack complexity is high, attack requirements are present, privileges required are high, user interaction required is none. The impact to confidentiality is none, the impact to availability is low, and the impact to system integrity is high.
CVSS 4.0 Vector String: https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
For v13.x customers: The attacks can be mitigated by installing the update and following our recommendations for securely configuring network access to the administrative console.
For v12.x and v11.x customers: A security update is not planned. Please upgrade to the most recent Secure Access version to maximize the security posture of your deployment.
Absolute recommends that customers schedule a maintenance window to update their Secure Access servers to 13.52 as soon as possible. Secure Access SaaS customers will be updated automatically during an upcoming maintenance window.
For more information, contact [email protected] or [email protected]