First published: Mon Oct 14 2024(Updated: )
A dynamic search for a prerequisite library could allow the possibility for an attacker to replace the correct file under some circumstances.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM BigFix Platform | >=9.5<9.5.25 | |
IBM BigFix Platform | >=10.0.0<10.0.12 | |
IBM BigFix Platform | >=11.0.0<11.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-30117 is significant due to the potential for an attacker to replace the correct prerequisite library file.
To fix CVE-2024-30117, ensure you update your HCLtech Bigfix Platform to a version that is beyond the vulnerable ranges specified in the CVE.
CVE-2024-30117 affects HCLtech Bigfix Platform versions between 9.5 and 10.0.12, as well as versions up to 11.0.3.
CVE-2024-30117 is a vulnerability that involves a dynamic search mechanism that could be exploited to replace necessary library files.
An attacker could exploit CVE-2024-30117 by leveraging the dynamic search for prerequisite libraries to insert malicious files.