A vulnerability has been identified in Polarion ALM (All versions < V2404.0). The affected product is vulnerable due to weak file and folder permissions in the installation path. An attacker with local access could exploit this vulnerability to escalate privileges to NT AUTHORITY\SYSTEM.
History

Fri, 18 Oct 2024 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Siemens
Siemens polarion Alm
CPEs cpe:2.3:a:siemens:polarion_alm:*:*:*:*:*:*:*:*
Vendors & Products Siemens
Siemens polarion Alm

cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published: 2024-02-13T09:00:02.735Z

Updated: 2024-08-02T22:09:49.946Z

Reserved: 2023-12-05T16:42:20.988Z

Link: CVE-2023-50236

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2024-02-13T09:15:46.633

Modified: 2024-10-18T17:20:38.727

Link: CVE-2023-50236

cve-icon Redhat

No data.