CVE-2024-37779

HIGH

WoodWing Elvis DAM <6.98.1 - Authenticated RCE

Title source: llm
STIX 2.1

Description

WoodWing Elvis DAM v6.98.1 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the Apache Ant script functionality.

Scores

CVSS v3 8.8
EPSS 0.0107
EPSS Percentile 60.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-75 CWE-94
Status published
Published Sep 23, 2024
Tracked Since Feb 18, 2026