CVE-2024-25011: Ericsson Catalog Manager and Ericsson Order Care - Exposure of Sensitive Information Vulnerability
Ericsson Catalog Manager and Ericsson Order Care APIs do not have authentication enabled by default. Authentication checks can be configured to remediate the information disclosure issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25011?
CVE-2024-25011 is categorized as a high severity vulnerability due to the lack of default authentication.
How do I fix CVE-2024-25011?
To remediate CVE-2024-25011, configure authentication checks for the affected APIs in Ericsson Catalog Manager and Ericsson Order Care.
What are the affected products for CVE-2024-25011?
The affected products for CVE-2024-25011 are Ericsson Catalog Manager and Ericsson Order Care.
What kind of issue is described in CVE-2024-25011?
CVE-2024-25011 describes an information disclosure issue resulting from missing default authentication checks.
Who is affected by CVE-2024-25011?
Organizations using Ericsson Catalog Manager and Ericsson Order Care without enabled authentication are affected by CVE-2024-25011.