A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.4). The application insufficiently validates user input for database read queries. This could allow an authenticated remote attacker to conduct an SQL injection attack that bypasses authorization controls and allows to download any data from the application's database.
Metrics
Affected Vendors & Products
References
History
Tue, 13 May 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 13 May 2025 09:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.4). The application insufficiently validates user input for database read queries. This could allow an authenticated remote attacker to conduct an SQL injection attack that bypasses authorization controls and allows to download any data from the application's database. | |
Weaknesses | CWE-89 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: siemens
Published: 2025-05-13T09:38:21.392Z
Updated: 2025-05-13T19:03:52.314Z
Reserved: 2024-10-28T07:01:23.766Z
Link: CVE-2024-51444

Updated: 2025-05-13T19:03:37.953Z

Status : Awaiting Analysis
Published: 2025-05-13T10:15:21.340
Modified: 2025-05-13T19:35:18.080
Link: CVE-2024-51444

No data.