Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.
Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as that user. This issue affects on-premises deployments only.
Affected productsDelinea Secret Server on-prem 10.6.0 through 11.7.61 11.8.0 through 11.8.1 11.9.0 through 11.9.47 12.0.0 through 12.0.22 12.1.0 through 12.1.2 Resolution:Upgrade to secret server version 12.2.7 or later, or upgrade to one of the following hotfixes: 12.1.3, 12.0.23, 11.9.48, 11.8.2, or 11.7.62.Customers on versions prior to 11.7 should upgrade to a supported version to address this vulnerability
Fixed versionsUpgrade to secret server version 12.2.7 or later, or upgrade to one of the following hotfixes: 12.1.3, 12.0.23, 11.9.48, 11.8.2, or 11.7.62.Customers on versions prior to 11.7 should upgrade to a supported version to address this vulnerability
Vendor guidance
Upgrade to secret server version 12.2.7 or later, or upgrade to one of the following hotfixes: 12.1.3, 12.0.23, 11.9.48, 11.8.2, or 11.7.62.Customers on versions prior to 11.7 should upgrade to a supported version to ...
Improper Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') in Delinea Inc. Cloud Suite and Privileged Access Service. If you're not using the latest Server Suite agents, this fix requires that you upgrade to Server Suite 2023.1 (agent 6.0.1) or later. If ...
Affected productsDelinea Cloud Suite and Privileged Access Service version 25.1 HF4 and earlier
Fixed versionsUpgrade to version 25.1 HF5 or later
Improper Authentication vulnerability in Delinea Inc. Secret Server On-Prem (RPC Password Rotation modules). This issue affects Secret Server On-Prem: 11.8.1, 11.9.6, 11.9.25.
Affected productsDelinea Secret Server on-prem versions 11.8.1, 11.9.6, and 11.9.25
Fixed versionsUpgrade to Secret Server version 11.9.47 or later The secret will remain checked out when the password change fails.
Vendor guidance
Upgrade to Secret Server version 11.9.47 or later The secret will remain checked out when the password change fails.
The distributed engine of Secret Server version 11.7.49 and earlier allows an attacker to impersonate another distributed engine by exploiting a vulnerability in an initial authorization event.
Affected productsDelinea Secret Server on-prem version 11.7.49 and earlier ResolutionUpgrade to Secret Server version 11.7.60 or later
Fixed versionsUpgrade to Secret Server version 11.7.60 or later
Secret Server version 11.7.49 and earlier allows an administrator to gain access to restricted tables by exploiting a vulnerability in the SQL report creation functionality.
Affected productsDelinea Secret Server on-prem version 11.7.49 and earlier ResolutionUpgrade to Secret Server version 11.7.60 or later
Fixed versionsUpgrade to Secret Server version 11.7.60 or later
We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.
Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.