CVE-2023-4501

CRITICALCVSS 9.8/10EPSS 0.62%

Last modified

CVE-2023-4501 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. User authentication with username and password credentials is ineffective in OpenText (Micro Focus) Visual COBOL, COBOL Server, Enterprise Developer, and Enterprise Server (including product variants such as Enterprise Test Server), versions 7.0 patch updates 19 and 20, 8.0 patch updates 8 and 9, and 9.0 patch update 1, when LDAP-based authentication is used with certain configurations. When the vulnerability is active, authentication succeeds with any valid username, regardless of whether the password is correct; it may also succeed with an invalid username (and any password). EPSS estimates a 0.62% chance of exploitation in the next 30 days.

Description

User authentication with username and password credentials is ineffective in OpenText (Micro Focus) Visual COBOL, COBOL Server, Enterprise Developer, and Enterprise Server (including product variants such as Enterprise Test Server), versions 7.0 patch updates 19 and 20, 8.0 patch updates 8 and 9, and 9.0 patch update 1, when LDAP-based authentication is used with certain configurations. When the vulnerability is active, authentication succeeds with any valid username, regardless of whether the password is correct; it may also succeed with an invalid username (and any password). This allows an attacker with access to the product to impersonate any user. Mitigations: The issue is corrected in the upcoming patch update for each affected product. Product overlays and workaround instructions are available through OpenText Support. The vulnerable configurations are believed to be uncommon. Administrators can test for the vulnerability in their installations by attempting to sign on to a Visual COBOL or Enterprise Server component such as ESCWA using a valid username and incorrect password.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.62%

45.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
MicrofocusCobol Server7.0Patch Update 19
MicrofocusCobol Server8.0Patch Update 8
MicrofocusCobol Server9.0Patch Update 1
MicrofocusEnterprise Developer7.0Patch Update 19
MicrofocusEnterprise Developer8.0Patch Update 8
MicrofocusEnterprise Developer9.0Patch Update 1
MicrofocusEnterprise Server7.0Patch Update 19
MicrofocusEnterprise Server8.0Patch Update 8
MicrofocusEnterprise Server9.0Patch Update 1
MicrofocusEnterprise Test Server7.0Patch Update 19
MicrofocusEnterprise Test Server8.0Patch Update 8
MicrofocusEnterprise Test Server9.0Patch Update 1
MicrofocusVisual Cobol7.0Patch Update 19
MicrofocusVisual Cobol8.0Patch Update 8
MicrofocusVisual Cobol9.0Patch Update 1

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2023-4501?
User authentication with username and password credentials is ineffective in OpenText (Micro Focus) Visual COBOL, COBOL Server, Enterprise Developer, and Enterprise Server (including product variants such as Enterprise Test Server), versions 7.0 patch updates 19 and 20, 8.0 patch updates 8 and 9, and 9.0 patch update 1, when LDAP-based authentication is used with certain configurations. When the vulnerability is active, authentication succeeds with any valid username, regardless of whether the password is correct; it may also succeed with an invalid username (and any password). This allows an attacker with access to the product to impersonate any user. Mitigations: The issue is corrected in the upcoming patch update for each affected product. Product overlays and workaround instructions are available through OpenText Support. The vulnerable configurations are believed to be uncommon. Administrators can test for the vulnerability in their installations by attempting to sign on to a Visual COBOL or Enterprise Server component such as ESCWA using a valid username and incorrect password.
How severe is CVE-2023-4501?
CVE-2023-4501 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 0.62% probability of exploitation in the next 30 days.
How do I fix CVE-2023-4501?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2023-4501?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST