CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-1969: Request approval spoofing in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center

4.3 CVSS

Description

Improper request input validation in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center allows a user to modify a valid request and spoof an approval in TEAM.

Upgrade TEAM to the latest release v.1.2.2. Follow instructions in updating TEAM documentation for updating process

Classification

CVE ID: CVE-2025-1969

CVSS Base Severity: MEDIUM

CVSS Base Score: 4.3

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Problem Types

CWE-346 Origin Validation Error

Affected Products

Vendor: AWS

Product: Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.02% (probability of being exploited)

EPSS Percentile: 1.4% (scored less or equal to compared to others)

EPSS Date: 2025-04-02 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-1969
https://github.com/aws-samples/iam-identity-center-team/security/advisories/GHSA-x9xv-r58p-qh86
https://aws.amazon.com/security/security-bulletins/AWS-2025-004/

Timeline