First published: Tue Feb 13 2024(Updated: )
A vulnerability has been identified in Polarion ALM (All versions < V2404.0). The affected product is vulnerable due to weak file and folder permissions in the installation path. An attacker with local access could exploit this vulnerability to escalate privileges to NT AUTHORITY\SYSTEM.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Polarion ALM | <2404.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-50236 has a high severity level due to its potential for privilege escalation.
To resolve CVE-2023-50236, update to Polarion ALM version 2404.0 or later.
CVE-2023-50236 affects all versions of Polarion ALM prior to version 2404.0.
An attacker needs local access to exploit CVE-2023-50236.
Exploiting CVE-2023-50236 allows an attacker to escalate privileges to NT AUTHORITY\SYSTEM.