CVE-2024-41767
CVSS 3.1 Score 7.3 of 10 (high)
Details
Published Jan 4, 2025
CWE ID 89
Summary
CVE-2024-41767 is a new SQL injection vulnerability affecting IBM Engineering Lifecycle Optimization - Publishing versions 7.0.2 and 7.0.3. This issue allows malicious actors to send crafted SQL statements, which can be exploited to gain unauthorized access to the back-end database. The vulnerability potentially enables attackers to view, add, modify, or delete sensitive information. IBM strongly recommends users to install the latest patches to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- IBM Corporation