An issue in NCR Terminal Handler 1.5.1 allows a low-level privileged authenticated attacker to query the SOAP API endpoint to obtain information about all of the users of the application including their usernames, roles, security groups and account statuses.
CVSS
No CVSS.
References
Link | Resource |
---|---|
https://drive.google.com/file/d/1-BDd0ycuYhuxo-lg4th-Cswimoqqzkot/view?usp=sharing | Permissions Required |
https://github.com/pwahba/cve-research/blob/main/CVE-2023-47298/CVE-2023-47298.md | Third Party Advisory |
Configurations
History
26 Jun 2025, 12:44
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:ncr:terminal_handler:1.5.1:*:*:*:*:*:*:* | |
First Time |
Ncr
Ncr terminal Handler |
|
References | () https://github.com/pwahba/cve-research/blob/main/CVE-2023-47298/CVE-2023-47298.md - Third Party Advisory | |
References | () https://drive.google.com/file/d/1-BDd0ycuYhuxo-lg4th-Cswimoqqzkot/view?usp=sharing - Permissions Required |
23 Jun 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-06-23 15:15
Updated : 2025-06-26 12:44
NVD link : CVE-2023-47298
Mitre link : CVE-2023-47298
JSON object : View
Products Affected
ncr
- terminal_handler
CWE
No CWE.