Delinea Secret Server before 11.7.000001 allows attackers...
        
  High severity
        
          Unreviewed
      
        Published
          Apr 29, 2024 
          to the GitHub Advisory Database
          •
          Updated Feb 12, 2025 
      
  
Description
        Published by the National Vulnerability Database
      Apr 28, 2024 
    
  
        Published to the GitHub Advisory Database
      Apr 29, 2024 
    
  
        Last updated
      Feb 12, 2025 
    
  
Delinea Secret Server before 11.7.000001 allows attackers to bypass authentication via the SOAP API in SecretServer/webservices/SSWebService.asmx. This is related to a hardcoded key, the use of the integer 2 for the Admin user, and removal of the oauthExpirationId attribute.
References