CVE-2024-0396: Missing Server-Side Input Validation in HTTP Parameter
In Progress MOVEit Transfer versions released before 2022.0.10 (14.0.10), 2022.1.11 (14.1.11), 2023.0.8 (15.0.8), 2023.1.3 (15.1.3), an input validation issue was discovered. An authenticated user can manipulate a parameter in an HTTPS transaction. The modified transaction could lead to computational errors within MOVEit Transfer and potentially result in a denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0396?
CVE-2024-0396 is considered a significant vulnerability that poses risks to the integrity of data transactions in affected versions of MOVEit Transfer.
How do I fix CVE-2024-0396?
To fix CVE-2024-0396, upgrade to MOVEit Transfer versions 2022.0.10, 2022.1.11, 2023.0.8, or 2023.1.3 or later.
Who is affected by CVE-2024-0396?
CVE-2024-0396 affects users of Progress MOVEit Transfer versions prior to those specified in the fix.
What impact does CVE-2024-0396 have on users?
CVE-2024-0396 allows authenticated users to manipulate parameters in HTTPS transactions, potentially leading to unauthorized access or data breaches.
When was CVE-2024-0396 discovered?
CVE-2024-0396 was discovered in the early months of 2024, affecting outdated versions of MOVEit Transfer.