{"id":1582,"date":"2025-01-28T10:04:55","date_gmt":"2025-01-28T10:04:55","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/01\/28\/critical-one-identity-manager-vulnerability-let-attackers-escalate-privileges\/"},"modified":"2025-01-28T10:04:55","modified_gmt":"2025-01-28T10:04:55","slug":"critical-one-identity-manager-vulnerability-let-attackers-escalate-privileges","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/01\/28\/critical-one-identity-manager-vulnerability-let-attackers-escalate-privileges\/","title":{"rendered":"Critical One Identity Manager Vulnerability Let Attackers Escalate Privileges"},"content":{"rendered":"<p>    Critical One Identity Manager Vulnerability Let Attackers Escalate Privileges<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A critical Insecure Direct Object Reference (IDOR) vulnerability has been identified in One Identity Manager, a widely used identity and access management solution.\u00a0<\/p>\n<p>This vulnerability, officially tracked as CVE-2024-56404, allows unauthorized <a href=\"https:\/\/i1.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhmKNqvR-BVyiyeIaACoan7yzyPHTl-PooeNBp1Y07Qhg-jdfWQUQVgANKTfNjzg3nKXD0Infkg_2j0z3PztCo318r98YfM-M3bgo1w9FmOesODPwjeblQB4scNnNCHY-ZYY7aZVFnDULfqkRX0TIVkcxSivZDsH_Uo71109g-Ttn5KPUKJH2wjPw7C0jfk\/s16000\/Windows%20File%20Explorer%20Vulnerability%20Exploited%20.png?w=356&amp;resize=356,364&amp;ssl=1\" target=\"_blank\" rel=\"noreferrer noopener\">privilege escalation<\/a> under specific configurations.\u00a0<\/p>\n<p>The issue affects only On-Premise installations and does not impact customers using the <a href=\"https:\/\/cybersecuritynews.com\/identity-management-solutions\/\" target=\"_blank\" rel=\"noreferrer noopener\">Identity Manager<\/a> On Demand or Starling Edition.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Understanding the Vulnerability<\/strong><\/h2>\n<p>The IDOR vulnerability arises when applications fail to enforce proper access control mechanisms on user-supplied input, such as object references in URLs or parameters.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 96%,rgb(169,184,195) 100%)\"><strong>Are you from SOC\/DFIR Teams? \u2013\u00a0Analyse Malware Files &amp; Links with ANY.RUN Sandox -&gt;\u00a0<a href=\"https:\/\/any.run\/demo\/?utm_source=li_csn&amp;utm_medium=post&amp;utm_campaign=video_meme&amp;utm_content=demo&amp;utm_term=270125\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Try for Free<\/a><\/strong><\/p>\n<p>Attackers can exploit this by manipulating object identifiers to gain unauthorized access to resources or escalate privileges. In the context of Identity Manager, this could allow attackers to:<\/p>\n<ul class=\"wp-block-list\">\n<li>Access administrative functionalities.<\/li>\n<li>Modify user roles to assign themselves higher privileges.<\/li>\n<li>Exploit sensitive configuration files.<\/li>\n<\/ul>\n<p>Such <a href=\"https:\/\/cybersecuritynews.com\/top-10-vulnerabilities-that-were-exploited-the-most-in-2023\/\" target=\"_blank\" rel=\"noreferrer noopener\">vulnerabilities<\/a> are particularly dangerous when chained with other exploits, enabling attackers to achieve vertical privilege escalation, where they gain access to higher-level permissions than initially granted.<\/p>\n<p>The vulnerability impacts customers using One Identity Manager versions 9.0.x through 9.2.1. Specifically:<\/p>\n<ul class=\"wp-block-list\">\n<li>Versions 9.0.x LTS requires the application of CU3 (Cumulative Update 3) before installing the hotfix.<\/li>\n<li>Customers using versions 9.1x and 9.2.x are also vulnerable.<\/li>\n<\/ul>\n<p>It is critical for affected organizations to address this flaw immediately to prevent potential exploitation.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Resolution and Mitigation<\/strong><\/h2>\n<p>One Identity has <a href=\"https:\/\/support.oneidentity.com\/product-notification\/noti-00001678\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">released<\/a> hotfixes for all the impacted versions to address this <a href=\"https:\/\/cybersecuritynews.com\/fortios-auth-bypass-vulnerability-exploited\/\" target=\"_blank\" rel=\"noreferrer noopener\">vulnerability<\/a>. Customers are urged to:<\/p>\n<p>Apply the relevant hotfix for their version,<\/p>\n<ol class=\"wp-block-list\"><\/ol>\n<ul class=\"wp-block-list\">\n<li>9.0.x LTS CU3<\/li>\n<li>9.1x<\/li>\n<li>9.2.x<\/li>\n<\/ul>\n<p>Alternatively, upgrade to version 9.3, which resolves the vulnerability entirely.<\/p>\n<p>The hotfixes include robust access control mechanisms designed to mitigate IDOR risks by validating user permissions before granting access to sensitive resources.<\/p>\n<p>Exploiting IDOR vulnerabilities can lead to severe consequences, including unauthorized data access, account takeovers, and system compromise.<\/p>\n<p>Hence, by addressing these vulnerabilities proactively, organizations can safeguard their systems against privilege escalation threats and maintain robust security postures.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 89%,rgb(169,184,195) 100%)\"><strong><strong>Integrating Application Security into Your CI\/CD Workflows Using Jenkins &amp; Jira -&gt;\u00a0<a href=\"https:\/\/webinars.indusface.com\/agile-security-workflows-devsecops-hacks-for-ci-cd-pipeline\/register?utm_source=gbhackers-blog-cta&amp;utm_campaign=2025-jan-webinar-agile-security&amp;utm_medium=referral\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Free Webinar<\/a><\/strong><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/one-identity-manager-privilege-escalation\/\">Critical One Identity Manager Vulnerability Let Attackers Escalate Privileges<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Kaaviya Ragupathy<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/one-identity-manager-privilege-escalation\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Critical One Identity Manager Vulnerability Let Attackers Escalate Privileges A critical Insecure Direct Object Reference (IDOR) vulnerability has been identified in One Identity Manager, a widely used identity and access management solution.\u00a0 This vulnerability, officially tracked as CVE-2024-56404, allows unauthorized privilege escalation under specific configurations.\u00a0 The issue affects only On-Premise installations and does not impact [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649,131],"tags":[130],"class_list":["post-1582","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","category-vulnerability","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/1582"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=1582"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/1582\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=1582"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=1582"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=1582"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}