5.3
CVE-2024-4837
- EPSS 0.17%
- Veröffentlicht 15.05.2024 17:15:16
- Zuletzt bearbeitet 16.01.2025 17:05:52
- Quelle security@progress.com
- CVE-Watchlists
- Unerledigt
Trust Boundary Violation Vulnerability
In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via a trust boundary violation vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Progress ≫ Telerik Report Server Version < 10.1.24.514
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.392 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
| security@progress.com | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.