CVE-2024-23733

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jan 29, 2025
Updated: Jan 31, 2025
CWE ID 522

Summary

CVE-2024-23733 is a vulnerability affecting Software AG's webMethods Integration Server version 10.15.0 and below. Attackers can exploit this issue by sending an arbitrary username and an empty password to the /WmAdmin/#/login/ URI in the /WmAdmin/,/invoke/vm.server/login login page. Successful exploitation grants unauthorized access to the administration panel, allowing attackers to discover the hostname and version information of the targeted system. This vulnerability poses a significant risk for potential unauthorized system access and data exposure. It is strongly recommended that users apply the relevant patch or upgrade to a secure version as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share