Cyber Posture

CVE-2024-41767

High

Published: 04 January 2025

Published
04 January 2025
Modified
21 March 2025
KEV Added
Patch
CVSS Score 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS Score 0.0011 29.1th percentile
Risk Priority 15 60% EPSS · 20% KEV · 20% CVSS

Description

IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

Security Summary

CVE-2024-41767 is a SQL injection vulnerability (CWE-89) in IBM Engineering Lifecycle Optimization - Publishing versions 7.0.2 and 7.0.3. Published on 2025-01-04, it carries a CVSS v3.1 base score of 7.3 (High: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L), indicating network accessibility with low attack complexity and no prerequisites.

A remote attacker could exploit this by sending specially crafted SQL statements to the application, potentially viewing, adding, modifying, or deleting information in the back-end database. No user privileges or interaction are needed, enabling unauthorized low-level impacts on confidentiality, integrity, and availability without scope changes.

The IBM security advisory at https://www.ibm.com/support/pages/node/7180199 provides details on patches and mitigation steps.

Details

CWE(s)
CWE-89

Affected Products

ibm
engineering lifecycle optimization publishing
7.0.2, 7.0.3

References