An authorization bypass through user-controlled key vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2024x allows an authenticated attacker to access some unauthorized data.
History

Wed, 16 Oct 2024 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Oct 2024 11:45:00 +0000

Type Values Removed Values Added
Description An authorization bypass through user-controlled key vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2024x allows an authenticated attacker to access some unauthorized data.
Title Authorization Bypass Through User-Controlled Key vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2024x
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: 3DS

Published: 2024-10-16T11:28:50.444Z

Updated: 2024-10-16T16:11:10.021Z

Reserved: 2024-08-21T11:31:17.911Z

Link: CVE-2024-8040

cve-icon Vulnrichment

Updated: 2024-10-16T16:11:05.859Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-10-16T12:15:09.013

Modified: 2024-10-16T16:38:14.557

Link: CVE-2024-8040

cve-icon Redhat

No data.