CVE-2024-8040: Authorization Bypass Through User-Controlled Key vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2024x
Published Oct 16, 2024
·Updated
An authorization bypass through user-controlled key vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2024x allows an authenticated attacker to access some unauthorized data.
Affected Software
1 affected component
Dassault Systèmes 3DEXPERIENCE
Event History
Oct 16, 2024
CVE Published
via MITRE·11:28 AM
Data Sourced
via MITRE·11:28 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-8040?
CVE-2024-8040 has been rated as a high severity vulnerability due to its potential for unauthorized data access.
2
How can I fix CVE-2024-8040?
To mitigate CVE-2024-8040, update to the latest version of the 3DEXPERIENCE platform as per vendor advisories.
3
What is the impact of CVE-2024-8040?
CVE-2024-8040 allows authenticated attackers to bypass authorization controls and access unauthorized data.
4
Who is affected by CVE-2024-8040?
Organizations using the 3DSwym application within the 3DEXPERIENCE R2024x platform may be affected by CVE-2024-8040.
5
Is CVE-2024-8040 being actively exploited?
As of now, there is no public information indicating that CVE-2024-8040 is being actively exploited in the wild.