go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Ragic Enterprise Cloud Database - Missing Authentication

TVN ID TVN-202410014
CVE ID CVE-2024-9984
CVSS 9.8 (Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products Ragic Enterprise Cloud Database before version 2024/08/08 09:45:25
Description Enterprise Cloud Database from Ragic does not authenticate access to specific functionality, allowing unauthenticated remote attackers to use this functionality to obtain any user's session cookie.
Solution Update to version 2024/08/08 09:45:25 or later.
Credit Kun Xian Lin (DEVCORE)
Public Date 2024-10-15
Top