First published: Wed Feb 12 2025(Updated: )
In Progress® Telerik® Reporting versions prior to 2025 Q1 (19.0.25.211), information disclosure is possible by a local threat actor through an absolute path vulnerability.
Credit: security@progress.com
Affected Software | Affected Version | How to fix |
---|---|---|
Telerik Reporting | <19.0.25.211 | |
Telerik Report Server | <19.0.25.211 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-6097 has been categorized as a medium severity vulnerability.
To fix CVE-2024-6097, upgrade to Telerik Reporting version 2025 Q1 (19.0.25.211) or later.
CVE-2024-6097 exploits an absolute path vulnerability that could allow information disclosure by a local threat actor.
CVE-2024-6097 affects all Telerik Reporting versions prior to 2025 Q1 (19.0.25.211).
No, CVE-2024-6097 is exploitable only by a local threat actor.