CVE-2024-41979: High severity SmartClient Opcenter QL Home (SC) vulnerability
A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >= V13.2 < V2506), SOA Cockpit (All versions >= V13.2 < V2506). The affected application does not enforce mandatory authorization on some functionality level at server side. This could allow an authenticated attacker to gain complete access of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41979?
The severity of CVE-2024-41979 is currently classified as high due to its potential impact on unauthorized access.
How do I fix CVE-2024-41979?
To fix CVE-2024-41979, it is recommended to update to the latest version of the affected SmartClient modules above version 2506.
What versions of SmartClient are affected by CVE-2024-41979?
CVE-2024-41979 affects SmartClient modules Opcenter QL Home (SC), SOA Audit, and SOA Cockpit for all versions from 13.2 to below 2506.
What type of vulnerability is CVE-2024-41979?
CVE-2024-41979 is an authorization vulnerability that fails to enforce mandatory controls on certain functionalities.
Can CVE-2024-41979 lead to data breaches?
Yes, CVE-2024-41979 can lead to data breaches by allowing unauthorized users to access sensitive functionalities.