Description
This vulnerability exists in Apex Softcell LD DP Back Office due to improper validation of certain parameters (cCdslClicentcode and cLdClientCode) in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating parameters in the API request body leading to exposure of sensitive information belonging to other users.
Published: 2024-09-19
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Upgrade Apex Softcell LD DP Back Office to version 24.8.21.1

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-42268 This vulnerability exists in Apex Softcell LD DP Back Office due to improper validation of certain parameters (cCdslClicentcode and cLdClientCode) in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating parameters in the API request body leading to exposure of sensitive information belonging to other users.
History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.0013}

epss

{'score': 0.00138}


Thu, 26 Sep 2024 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Apexsoftcell ld Geo
Weaknesses NVD-CWE-Other
CPEs cpe:2.3:a:apexsoftcell:ld_geo:*:*:*:*:*:*:*:*
Vendors & Products Apexsoftcell ld Geo
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Fri, 20 Sep 2024 12:30:00 +0000

Type Values Removed Values Added
Description This vulnerability exists in Apex Softcell LD DP Back Office due to improper validation of certain parameters “cCdslClicentcode” and “cLdClientCode” in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating parameters in the API request body leading to exposure of sensitive information belonging to other users. This vulnerability exists in Apex Softcell LD DP Back Office due to improper validation of certain parameters (cCdslClicentcode and cLdClientCode) in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating parameters in the API request body leading to exposure of sensitive information belonging to other users.

Thu, 19 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Apexsoftcell
Apexsoftcell ld Dp Back Office
CPEs cpe:2.3:a:apexsoftcell:ld_dp_back_office:*:*:*:*:*:*:*:*
Vendors & Products Apexsoftcell
Apexsoftcell ld Dp Back Office
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 19 Sep 2024 06:45:00 +0000

Type Values Removed Values Added
Description This vulnerability exists in LD DP Back Office due to improper validation of certain parameters “cCdslClicentcode” and “cLdClientCode” in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating parameters in the API request body leading to exposure of sensitive information belonging to other users. This vulnerability exists in Apex Softcell LD DP Back Office due to improper validation of certain parameters “cCdslClicentcode” and “cLdClientCode” in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating parameters in the API request body leading to exposure of sensitive information belonging to other users.

Thu, 19 Sep 2024 06:00:00 +0000

Type Values Removed Values Added
Description This vulnerability exists in LD DP Back Office due to improper validation of certain parameters “cCdslClicentcode” and “cLdClientCode” in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating parameters in the API request body leading to exposure of sensitive information belonging to other users.
Title Parameter Manipulation Vulnerability
Weaknesses CWE-359
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N'}


Subscriptions

Apexsoftcell Ld Dp Back Office Ld Geo
cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-In

Published:

Updated: 2024-09-20T12:15:03.789Z

Reserved: 2024-09-18T08:36:36.214Z

Link: CVE-2024-47085

cve-icon Vulnrichment

Updated: 2024-09-19T14:23:13.090Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-19T06:15:02.960

Modified: 2024-09-26T15:30:47.787

Link: CVE-2024-47085

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses