Beveiligingsadvies

CVE-2024-51556

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2024-11-04 12:09:30
Laatst bijgewerkt 2024-11-22 11:44:55
Toegewezen door CERT-In
CVSS-score 7.1
Status PUBLISHED

Beschrijving

This vulnerability exists in the Wave 2.0 due to insufficient encryption of sensitive data received at the API response. An authenticated remote attacker could exploit this vulnerability by manipulating API input parameters through API request URL/payload leading to unauthorized access to sensitive information belonging to other users.