216.73.217.22

CVE-2024-9984

· Published 15/10/2024 09:15 · Modified 16/10/2024 22:03

Labels: CVE-2024-9984 2024-10-15CVE-2024-9984CWE-306[email protected]

Essential information

Published
15/10/2024 09:15
Modified
16/10/2024 22:03
Author
Creator
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

Enterprise Cloud Database from Ragic does not authenticate access to specific functionality, allowing unauthenticated remote attackers to use this functionality to obtain any user's session cookie.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
ragic / enterprise cloud database cpe:2.3:a:ragic:enterprise_cloud_database:*:*:*:*:*:*:*:*

References