First published: Tue Feb 13 2024(Updated: )
A vulnerability has been identified in Polarion ALM (All versions < V2404.0). The REST API endpoints of doorsconnector of the affected product lacks proper authentication. An unauthenticated attacker could access the endpoints, and potentially execute code.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Polarion ALM | <2404.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-23813 is considered a critical vulnerability due to its potential for unauthenticated access to sensitive REST API endpoints.
To fix CVE-2024-23813, upgrade to Polarion ALM version 2404.0 or later, which includes security improvements.
CVE-2024-23813 could allow unauthorized attackers to access REST API endpoints, leading to possible unauthorized code execution.
All versions of Polarion ALM prior to 2404.0 are affected by CVE-2024-23813.
No, CVE-2024-23813 can be exploited by unauthenticated attackers due to the lack of proper authentication on the API endpoints.