SB20241015235 - Improper access control in Sakai
Published: October 15, 2024 Updated: April 28, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper access control (CVE-ID: CVE-2024-47876)
The vulnerability allows a remote attacker to gain unauthorized access to the system.
The vulnerability exists due to improper access control in kernel user account handling when processing logins for users created with the type roleview. A remote attacker can authenticate using such an account to gain unauthorized access to the system.
Remediation
Install update from vendor's website.