CVE-2024-23813: Critical severity Siemens Polarion Alm vulnerability
A vulnerability has been identified in Polarion ALM (All versions < V2404.0). The REST API endpoints of doorsconnector of the affected product lacks proper authentication. An unauthenticated attacker could access the endpoints, and potentially execute code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23813?
CVE-2024-23813 is considered a critical vulnerability due to its potential for unauthenticated access to sensitive REST API endpoints.
How do I fix CVE-2024-23813?
To fix CVE-2024-23813, upgrade to Polarion ALM version 2404.0 or later, which includes security improvements.
What types of attacks can CVE-2024-23813 enable?
CVE-2024-23813 could allow unauthorized attackers to access REST API endpoints, leading to possible unauthorized code execution.
Which versions of Polarion ALM are affected by CVE-2024-23813?
All versions of Polarion ALM prior to 2404.0 are affected by CVE-2024-23813.
Is authentication required to exploit CVE-2024-23813?
No, CVE-2024-23813 can be exploited by unauthenticated attackers due to the lack of proper authentication on the API endpoints.