Enterprise Cloud Database from Ragic does not properly validate a specific page parameter, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.

Project Subscriptions

Vendors Products
Enterprise Cloud Database Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2024-50262 Enterprise Cloud Database from Ragic does not properly validate a specific page parameter, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.
Fixes

Solution

Update to version 2024/08/08 09:45:25 or later.


Workaround

No workaround given by the vendor.

History

Wed, 16 Oct 2024 22:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22

Tue, 15 Oct 2024 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Ragic
Ragic enterprise Cloud Database
CPEs cpe:2.3:a:ragic:enterprise_cloud_database:*:*:*:*:*:*:*:*
Vendors & Products Ragic
Ragic enterprise Cloud Database
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Oct 2024 08:30:00 +0000

Type Values Removed Values Added
Description Enterprise Cloud Database from Ragic does not properly validate a specific page parameter, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.
Title Ragic Enterprise Cloud Database - Arbitrary File Read through Path Traversal
Weaknesses CWE-23
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2024-10-15T13:40:00.636Z

Reserved: 2024-10-15T06:58:02.811Z

Link: CVE-2024-9983

cve-icon Vulnrichment

Updated: 2024-10-15T13:39:54.595Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-15T09:15:04.243

Modified: 2024-10-16T22:03:42.020

Link: CVE-2024-9983

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses