Vulnerabilities > CVE-2021-28488 - Exposure of Resource to Wrong Sphere vulnerability in Ericsson Network Manager
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
Ericsson Network Manager (ENM) before 21.2 has incorrect access-control behavior (that only affects the level of access available to persons who were already granted a highly privileged role). Users in the same AMOS authorization group can retrieve managed-network data that was not set to be accessible to the entire group (i.e., was only set to be accessible to a subset of that group).
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |