CVE-2024-9984

CRITICAL

Enterprise Cloud Database - Info Disclosure

Title source: llm
STIX 2.1

Description

Enterprise Cloud Database from Ragic does not authenticate access to specific functionality, allowing unauthenticated remote attackers to use this functionality to obtain any user's session cookie.

References (2)

Core 2
Core References
Third Party Advisory third-party-advisory
https://www.twcert.org.tw/tw/cp-132-8150-c955a-1.html
Third Party Advisory third-party-advisory
https://www.twcert.org.tw/en/cp-139-8151-1a4b5-2.html

Scores

CVSS v3 9.8
EPSS 0.0055
EPSS Percentile 41.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-306
Status published
Products (1)
ragic/enterprise_cloud_database < 2024-08-08
Published Oct 15, 2024
Tracked Since Feb 18, 2026