CVE-2024-8015: Telerik Report Server Insecure Type Resolution
Published Oct 9, 2024
·Updated
In Progress Telerik Report Server versions prior to 2024 Q3 (10.2.24.924), a remote code execution attack is possible through object injection via an insecure type resolution vulnerability.
Affected Software
1 affected component
Progress Telerik Report Server<10.2.24.924
Event History
Oct 9, 2024
CVE Published
via MITRE·02:49 PM
Data Sourced
via MITRE·02:49 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-8015?
CVE-2024-8015 is classified as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2024-8015?
To remediate CVE-2024-8015, upgrade to Progress Telerik Report Server version 2024 Q3 (10.2.24.924) or later.
3
What impact does CVE-2024-8015 have on affected systems?
CVE-2024-8015 allows attackers to perform remote code execution through object injection, potentially compromising the entire server.
4
Which versions of Telerik Report Server are vulnerable to CVE-2024-8015?
Versions of Progress Telerik Report Server prior to 2024 Q3 (10.2.24.924) are affected by CVE-2024-8015.
5
Can CVE-2024-8015 be exploited remotely?
Yes, CVE-2024-8015 can be exploited remotely, making it particularly dangerous for unpatched servers.