CVE-2023-4501
Last modified
CVE-2023-4501 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. User authentication with username and password credentials is ineffective in OpenText (Micro Focus) Visual COBOL, COBOL Server, Enterprise Developer, and Enterprise Server (including product variants such as Enterprise Test Server), versions 7.0 patch updates 19 and 20, 8.0 patch updates 8 and 9, and 9.0 patch update 1, when LDAP-based authentication is used with certain configurations. When the vulnerability is active, authentication succeeds with any valid username, regardless of whether the password is correct; it may also succeed with an invalid username (and any password). EPSS estimates a 0.62% chance of exploitation in the next 30 days.
Description
User authentication with username and password credentials is ineffective in OpenText (Micro Focus) Visual COBOL, COBOL Server, Enterprise Developer, and Enterprise Server (including product variants such as Enterprise Test Server), versions 7.0 patch updates 19 and 20, 8.0 patch updates 8 and 9, and 9.0 patch update 1, when LDAP-based authentication is used with certain configurations. When the vulnerability is active, authentication succeeds with any valid username, regardless of whether the password is correct; it may also succeed with an invalid username (and any password). This allows an attacker with access to the product to impersonate any user. Mitigations: The issue is corrected in the upcoming patch update for each affected product. Product overlays and workaround instructions are available through OpenText Support. The vulnerable configurations are believed to be uncommon. Administrators can test for the vulnerability in their installations by attempting to sign on to a Visual COBOL or Enterprise Server component such as ESCWA using a valid username and incorrect password.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Microfocus | Cobol Server | 7.0 | Patch Update 19 |
| Microfocus | Cobol Server | 8.0 | Patch Update 8 |
| Microfocus | Cobol Server | 9.0 | Patch Update 1 |
| Microfocus | Enterprise Developer | 7.0 | Patch Update 19 |
| Microfocus | Enterprise Developer | 8.0 | Patch Update 8 |
| Microfocus | Enterprise Developer | 9.0 | Patch Update 1 |
| Microfocus | Enterprise Server | 7.0 | Patch Update 19 |
| Microfocus | Enterprise Server | 8.0 | Patch Update 8 |
| Microfocus | Enterprise Server | 9.0 | Patch Update 1 |
| Microfocus | Enterprise Test Server | 7.0 | Patch Update 19 |
| Microfocus | Enterprise Test Server | 8.0 | Patch Update 8 |
| Microfocus | Enterprise Test Server | 9.0 | Patch Update 1 |
| Microfocus | Visual Cobol | 7.0 | Patch Update 19 |
| Microfocus | Visual Cobol | 8.0 | Patch Update 8 |
| Microfocus | Visual Cobol | 9.0 | Patch Update 1 |
References
- https://portal.microfocus.com/s/article/KM000021287Vendor Advisory
- https://portal.microfocus.com/s/article/KM000021287Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-4501?
How severe is CVE-2023-4501?
How do I fix CVE-2023-4501?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-45004Unauth. Reflected Cross-Site Scripting (XSS) vulnerability i…6.1
- CVE-2023-45005Unauth. Reflected Cross-Site Scripting (XSS) vulnerability i…6.1
- CVE-2023-45006Unauth. Reflected Cross-Site Scripting (XSS) vulnerability i…6.1
- CVE-2023-45007Unauth. Reflected Cross-Site Scripting (XSS) vulnerability i…6.1
- CVE-2023-45008Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerabili…4.8
- CVE-2023-45009Improper Restriction of Excessive Authentication Attempts vu…5.3
- CVE-2023-45010Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerabili…4.8
- CVE-2023-45011Cross-Site Request Forgery (CSRF) vulnerability in Igor Buya…8.8
- CVE-2023-45012Online Bus Booking System v1.0 is vulnerable to multiple Una…9.8
- CVE-2023-45013Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2023-45014Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2023-45015Online Bus Booking System v1.0 is vulnerable to multiple Una…9.8
Are you affected by CVE-2023-4501?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
