Vulnerabilities (CVE)

Filtered by vendor Ericsson Subscribe
Filtered by product Network Manager
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-28488 1 Ericsson 1 Network Manager 2022-07-12 4.0 MEDIUM 6.5 MEDIUM
Ericsson Network Manager (ENM) before 21.2 has incorrect access-control behavior (that only affects the level of access available to persons who were already granted a highly privileged role). Users in the same AMOS authorization group can retrieve managed-network data that was not set to be accessible to the entire group (i.e., was only set to be accessible to a subset of that group).