PT-2024-27747 · Apache+1 · Apache Ant+1

Published

2024-09-23

·

Updated

2024-09-27

·

CVE-2024-37779

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WoodWing Elvis DAM version 6.98.1
Description The issue is related to an authenticated remote command execution through the Apache Ant script functionality. This allows for the execution of commands on the affected system.
Recommendations For WoodWing Elvis DAM version 6.98.1, consider disabling the Apache Ant script functionality as a temporary workaround until a patch is available. Restrict access to the vulnerable functionality to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-37779

Affected Products

Apache Ant
Woodwing Elvis Dam