CVE-2024-47085 Vulnerability Details

  /     /     /  

CVE-2024-47085 Metadata Quick Info

CVE Published: 19/09/2024 | CVE Updated: 20/09/2024 | CVE Year: 2024
Source: CERT-In | Vendor: Apex Softcell | Product: LD DP Back Office
Status : PUBLISHED

CVE-2024-47085 Description

This vulnerability exists in Apex Softcell LD DP Back Office due to improper validation of certain parameters (cCdslClicentcode and cLdClientCode) in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating parameters in the API request body leading to exposure of sensitive information belonging to other users.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-359
CWE Name: CWE-359: Exposure of Private Personal Information to an Unauthorized Actor
Source: Apex Softcell

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).