Horizon Alert
Summary of the vulnerability and why it matters
This vulnerability affects OpenText (Micro Focus) COBOL products when using LDAP for authentication with specific configurations. It allows an attacker to bypass password checks and impersonate any user, posing a significant risk if exploited. The vulnerable configurations are believed to be uncommon, and mitigation is available through OpenText Support.
- Authentication bypass allows any user to gain access.
- Critical risk of unauthorized user impersonation.
- Confirm relevance and exposure for affected systems.
Attack Path
How an attacker could exploit the issue
An attacker could gain access to systems running OpenText (Micro Focus) Visual COBOL, COBOL Server, Enterprise Developer, or Enterprise Server. If LDAP-based authentication is misconfigured, the attacker can bypass username and password checks to impersonate any user. This vulnerability, active when specific LDAP configurations are in place, could allow unauthorized access and control over user accounts.
- Unauthenticated network access is required.
- Authentication bypass via incorrect credentials.
- Unauthorized user impersonation and access.
Live Threat
Current exploitation, exposure, and threat context
When LDAP-based authentication is misconfigured, users could be impersonated by anyone with access to the affected OpenText (Micro Focus) products, regardless of their password. This could impact user session integrity and system access when these products are in use.
- User impersonation and unauthorized access.
- Any user with network access could attempt impersonation.
- Compromised user sessions and system integrity.
Operational Fix
Recommended remediation, mitigation, and detection steps
Understanding who is responsible for addressing this vulnerability involves identifying the teams that manage the OpenText (Micro Focus) Visual COBOL, COBOL Server, Enterprise Developer, and Enterprise Server environments. This could include application owners, infrastructure teams, or platform teams, depending on how these systems are deployed and managed within your organization. The initial practical step is to determine the presence of these affected products, assess their accessibility and criticality, and then locate the accountable owner to plan remediation actions based on risk.
- Identify affected system owners.
- Verify LDAP authentication configuration.
- Plan risk-based remediation strategy.