This vulnerability exists in Apex Softcell LD DP Back Office due to improper validation of certain parameters “cCdslClicentcode” and “cLdClientCode” in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating parameters in the API request body leading to exposure of sensitive information belonging to other users.
History

Thu, 19 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Apexsoftcell
Apexsoftcell ld Dp Back Office
CPEs cpe:2.3:a:apexsoftcell:ld_dp_back_office:*:*:*:*:*:*:*:*
Vendors & Products Apexsoftcell
Apexsoftcell ld Dp Back Office
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 19 Sep 2024 06:45:00 +0000

Type Values Removed Values Added
Description This vulnerability exists in LD DP Back Office due to improper validation of certain parameters “cCdslClicentcode” and “cLdClientCode” in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating parameters in the API request body leading to exposure of sensitive information belonging to other users. This vulnerability exists in Apex Softcell LD DP Back Office due to improper validation of certain parameters “cCdslClicentcode” and “cLdClientCode” in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating parameters in the API request body leading to exposure of sensitive information belonging to other users.

Thu, 19 Sep 2024 06:00:00 +0000

Type Values Removed Values Added
Description This vulnerability exists in LD DP Back Office due to improper validation of certain parameters “cCdslClicentcode” and “cLdClientCode” in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating parameters in the API request body leading to exposure of sensitive information belonging to other users.
Title Parameter Manipulation Vulnerability
Weaknesses CWE-359
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-In

Published: 2024-09-19T05:56:23.460Z

Updated: 2024-09-19T14:23:16.598Z

Reserved: 2024-09-18T08:36:36.214Z

Link: CVE-2024-47085

cve-icon Vulnrichment

Updated: 2024-09-19T14:23:13.090Z

cve-icon NVD

Status : Received

Published: 2024-09-19T06:15:02.960

Modified: 2024-09-19T07:15:02.050

Link: CVE-2024-47085

cve-icon Redhat

No data.