CVE-2024-9470: Cortex XSOAR: Information Disclosure Vulnerability (Severity: MEDIUM)
Published Oct 9, 2024
·Updated
A vulnerability in Cortex XSOAR allows the disclosure of incident data to users who do not have the privilege to view the data.
Affected Software
1 affected componentFixes available
Palo Alto Networks Cortex XSOAR<6.12.0 (Build 1271551), =6.12
6.12.0 (Build 1271551)
Remediation
Information
This issue is fixed in Cortex XSOAR 6.12.0 (Build 1271551), and all later Cortex XSOAR versions.
Event History
Oct 9, 2024
Advisory Published
via Palo Alto Networks·04:00 PM
CVE Published
via MITRE·05:06 PM
Data Sourced
via MITRE·05:06 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-9470?
CVE-2024-9470 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2024-9470?
To fix CVE-2024-9470, upgrade to Cortex XSOAR version 6.12.1 or later.
3
Who is affected by CVE-2024-9470?
CVE-2024-9470 affects users of Cortex XSOAR version 6.12.0 and earlier.
4
What type of vulnerability is CVE-2024-9470?
CVE-2024-9470 is a data disclosure vulnerability.
5
What kind of data can be disclosed due to CVE-2024-9470?
CVE-2024-9470 allows unauthorized users to access incident data.