CVE-2024-13929: Authenticated Servlet Command Injection
Published May 22, 2025
·Updated
Servlet injection vulnerabilities in ASPECT allow remote code execution if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.
Affected Software
3 affected components
ASPECT ASPECT-Enterprise<=3.08.03
ASPECT NEXUS Series<=3.08.03
ASPECT MATRIX Series<=3.08.03
Event History
May 22, 2025
CVE Published
via MITRE·05:53 PM
Data Sourced
via MITRE·05:53 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-13929?
CVE-2024-13929 has a high severity rating due to the potential for remote code execution.
2
How do I fix CVE-2024-13929?
To mitigate CVE-2024-13929, upgrade ASPECT-Enterprise, NEXUS Series, and MATRIX Series to versions above 3.08.03.
3
What systems are affected by CVE-2024-13929?
CVE-2024-13929 affects ASPECT-Enterprise, NEXUS Series, and MATRIX Series up to version 3.08.03.
4
What type of vulnerability is CVE-2024-13929?
CVE-2024-13929 is classified as a servlet injection vulnerability.
5
What could happen if CVE-2024-13929 is exploited?
If exploited, CVE-2024-13929 could allow an attacker to perform remote code execution, compromising sensitive data.