CVE-2024-8609

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Sep 27, 2024
Updated: Oct 4, 2024
CWE ID 532

Summary

CVE-2024-8609 is a log file vulnerability affecting Oceanic Software's ValeApp. Before version 2.0.0, the Query System in ValeApp is susceptible to the insertion of sensitive information into log files. An attacker can exploit this vulnerability to gain unauthorized access to critical data, potentially leading to significant security risks. The issue arises due to insufficient input validation in the Query System, enabling an attacker to modify the log files with malicious data. Organizations using ValeApp are advised to upgrade to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share