A vulnerability has been identified in Polarion ALM (All versions < V2404.0). The Apache Lucene based query engine in the affected application lacks proper access controls. This could allow an authenticated user to query items beyond the user's allowed projects.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: siemens
Published: 2024-05-14T10:03:08.350Z
Updated: 2024-08-02T02:36:04.542Z
Reserved: 2024-04-25T09:05:34.005Z
Link: CVE-2024-33647
Vulnrichment
Updated: 2024-05-14T14:17:04.245Z
NVD
Status : Awaiting Analysis
Published: 2024-05-14T16:17:21.700
Modified: 2024-05-14T19:17:55.627
Link: CVE-2024-33647
Redhat
No data.