CVE-2024-6097: Absolute Path Traversal Vulnerability
Published Feb 12, 2025
·Updated
In Progress® Telerik® Reporting versions prior to 2025 Q1 (19.0.25.211), information disclosure is possible by a local threat actor through an absolute path vulnerability.
Affected Software
2 affected components
Progress Telerik Reporting<19.0.25.211
Telerik Reporting<19.0.25.211
Event History
Feb 12, 2025
CVE Published
via MITRE·05:37 PM
Data Sourced
via MITRE·05:37 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-6097?
CVE-2024-6097 has been categorized as a medium severity vulnerability.
2
How do I fix CVE-2024-6097?
To fix CVE-2024-6097, upgrade to Telerik Reporting version 2025 Q1 (19.0.25.211) or later.
3
What does CVE-2024-6097 exploit?
CVE-2024-6097 exploits an absolute path vulnerability that could allow information disclosure by a local threat actor.
4
Which versions of Telerik Reporting are affected by CVE-2024-6097?
CVE-2024-6097 affects all Telerik Reporting versions prior to 2025 Q1 (19.0.25.211).
5
Can a remote attacker exploit CVE-2024-6097?
No, CVE-2024-6097 is exploitable only by a local threat actor.