Description
Enterprise Cloud Database from Ragic does not authenticate access to specific functionality, allowing unauthenticated remote attackers to use this functionality to obtain any user's session cookie.
Published: 2024-10-15
Score: 9.8 Critical
EPSS: 1.9% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update to version 2024/08/08 09:45:25 or later.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-50263 Enterprise Cloud Database from Ragic does not authenticate access to specific functionality, allowing unauthenticated remote attackers to use this functionality to obtain any user's session cookie.
History

Tue, 15 Oct 2024 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Ragic
Ragic enterprise Cloud Database
CPEs cpe:2.3:a:ragic:enterprise_cloud_database:*:*:*:*:*:*:*:*
Vendors & Products Ragic
Ragic enterprise Cloud Database
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Oct 2024 08:30:00 +0000

Type Values Removed Values Added
Description Enterprise Cloud Database from Ragic does not authenticate access to specific functionality, allowing unauthenticated remote attackers to use this functionality to obtain any user's session cookie.
Title Ragic Enterprise Cloud Database - Missing Authentication
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ragic Enterprise Cloud Database
cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2024-10-15T13:38:39.847Z

Reserved: 2024-10-15T06:58:04.062Z

Link: CVE-2024-9984

cve-icon Vulnrichment

Updated: 2024-10-15T13:38:35.867Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-15T09:15:04.480

Modified: 2024-10-16T22:03:23.407

Link: CVE-2024-9984

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses