This vulnerability exists in Apex Softcell LD Geo due to improper validation of the certain parameters (Client ID, DPID or BOID) in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating parameters in the API request body leading to exposure of sensitive information belonging to other users.
History

Thu, 19 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Apexsoftcell
Apexsoftcell ld Geo
CPEs cpe:2.3:a:apexsoftcell:ld_geo:*:*:*:*:*:*:*:*
Vendors & Products Apexsoftcell
Apexsoftcell ld Geo
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 19 Sep 2024 06:30:00 +0000

Type Values Removed Values Added
Description This vulnerability exists in Apex Softcell LD Geo due to improper validation of the certain parameters (Client ID, DPID or BOID) in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating parameters in the API request body leading to exposure of sensitive information belonging to other users.
Title Information Disclosure Vulnerability
Weaknesses CWE-359
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-In

Published: 2024-09-19T06:08:46.528Z

Updated: 2024-09-19T13:49:16.221Z

Reserved: 2024-09-18T08:36:36.215Z

Link: CVE-2024-47087

cve-icon Vulnrichment

Updated: 2024-09-19T13:49:11.539Z

cve-icon NVD

Status : Received

Published: 2024-09-19T07:15:02.360

Modified: 2024-09-19T07:15:02.360

Link: CVE-2024-47087

cve-icon Redhat

No data.