CVE-2024-56135: Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.
This issue affects:
Product
Affected Versions
LoadMaster
From 7.2.55.0 to 7.2.60.1 (inclusive)
From 7.2.49.0 to 7.2.54.12 (inclusive)
7.2.48.12 and all prior versions
ECS
All prior versions to 7.2.60.1 (inclusive)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-56135?
CVE-2024-56135 has a high severity due to the potential for OS Command Injection.
How do I fix CVE-2024-56135?
To mitigate CVE-2024-56135, upgrade Progress LoadMaster to a version that is not affected, such as those above 7.2.60.1.
What software is affected by CVE-2024-56135?
CVE-2024-56135 affects Progress LoadMaster versions from 7.2.49.0 to 7.2.60.1 and certain versions of Progress ECS.
Can CVE-2024-56135 allow unauthorized access?
Yes, CVE-2024-56135 can be exploited to execute arbitrary OS commands, potentially allowing unauthorized access.
Is there a workaround for CVE-2024-56135?
There are no known effective workarounds; the recommended action is to upgrade to an unaffected version.