ZeroHour

CVE-2024-23813

CVSS 3.1
9.8 critical
EPSS
<1%p46
Published
()
Modified
Description

A vulnerability has been identified in Polarion ALM (All versions < V2404.0). The REST API endpoints of doorsconnector of the affected product lacks proper authentication. An unauthenticated attacker could access the endpoints, and potentially execute code.

Vendors
siemens
Products
polarion alm
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.