CVE-2024-9984

Enterprise Cloud Database from Ragic does not authenticate access to specific functionality, allowing unauthenticated remote attackers to use this functionality to obtain any user's session cookie.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ragic:enterprise_cloud_database:*:*:*:*:*:*:*:*

History

16 Oct 2024, 22:03

Type Values Removed Values Added
CPE cpe:2.3:a:ragic:enterprise_cloud_database:*:*:*:*:*:*:*:*
References () https://www.twcert.org.tw/en/cp-139-8151-1a4b5-2.html - () https://www.twcert.org.tw/en/cp-139-8151-1a4b5-2.html - Third Party Advisory
References () https://www.twcert.org.tw/tw/cp-132-8150-c955a-1.html - () https://www.twcert.org.tw/tw/cp-132-8150-c955a-1.html - Third Party Advisory
Summary
  • (es) Enterprise Cloud Database de Ragic no autentica el acceso a una funcionalidad específica, lo que permite que atacantes remotos no autenticados utilicen esta funcionalidad para obtener la cookie de sesión de cualquier usuario.
First Time Ragic
Ragic enterprise Cloud Database

15 Oct 2024, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-15 09:15

Updated : 2024-10-16 22:03


NVD link : CVE-2024-9984

Mitre link : CVE-2024-9984

CVE.ORG link : CVE-2024-9984


JSON object : View

Products Affected

ragic

  • enterprise_cloud_database
CWE
CWE-306

Missing Authentication for Critical Function