CVE-2024-12105: WhatsUp Gold - SnmpExtendedActiveMonitor path traversal
Published Dec 31, 2024
·Updated
In WhatsUp Gold versions released before 2024.0.2, an authenticated user can use a specially crafted HTTP request that can lead to information disclosure.
Affected Software
1 affected component
Progress WhatsUp Gold>=23.1.0<24.0.2
Event History
Dec 31, 2024
CVE Published
via MITRE·10:32 AM
Data Sourced
via MITRE·10:32 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-12105?
CVE-2024-12105 has been rated as a medium severity vulnerability due to the potential for information disclosure.
2
How do I fix CVE-2024-12105?
To fix CVE-2024-12105, upgrade WhatsUp Gold to version 2024.0.2 or later.
3
Who is affected by CVE-2024-12105?
CVE-2024-12105 affects authenticated users of WhatsUp Gold versions prior to 2024.0.2.
4
What type of vulnerability is CVE-2024-12105?
CVE-2024-12105 is an information disclosure vulnerability due to specially crafted HTTP requests.
5
What versions of WhatsUp Gold are vulnerable to CVE-2024-12105?
WhatsUp Gold versions from 23.1.0 up to, but not including, 2024.0.2 are vulnerable to CVE-2024-12105.