PT-2024-27511 · Ab Initio · Ab Initio Authorization Gateway+1

Davide Turaccio

+1

·

Published

2024-08-08

·

Updated

2024-08-29

·

CVE-2024-37382

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ab Initio Metadata Hub and Authorization Gateway versions prior to 4.3.1.1
Description An issue in the import host feature allows attackers to run arbitrary code via crafted modification of server configuration.
Recommendations For versions prior to 4.3.1.1, update to version 4.3.1.1 or later to resolve the issue.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-37382

Affected Products

Ab Initio Authorization Gateway
Ab Initio Metadata Hub