PT-2024-34341 · Numerix · Numerix License Server
Daniel Hirschberger
·
Published
2024-12-11
·
Updated
2024-12-12
·
CVE-2024-50585
CVSS v3.1
4.7
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Numerix License Server (affected versions not specified)
Description:
The issue allows attackers to infect users with arbitrary JavaScript code that runs in the context of the "Numerix License Server Administration System Login" page (nlslogin.jsp) when they click on a malicious link or visit a website under the control of an attacker. This can be triggered by sending a specially crafted HTTP POST request to the
nlslogin.jsp page. The vendor has been unresponsive, and as a result, there is no available solution. Users are advised to restrict access and monitor logs.Recommendations:
To mitigate the risk, restrict access to the
nlslogin.jsp page and monitor logs for suspicious activity.
Try to reach out to your contact person for the Numerix vendor and request a patch.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Numerix License Server