ZeroHour

CVE-2024-11481

CVSS 3.1
8.2 high
EPSS
<1%p37
Published
()
Modified
Description

A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API. This leads to improper handling of path traversal, insecure forwarding to an AJP backend without adequate validation, and lack of authentication for accessing internal API endpoints.

Vendors
trellix
Products
enterprise security manager
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N

In the news

No ingested article mentions this CVE yet.