PT-2024-34341 · Numerix · Numerix License Server

Daniel Hirschberger

·

Published

2024-12-11

·

Updated

2024-12-12

·

CVE-2024-50585

CVSS v3.1

4.7

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Numerix License Server (affected versions not specified)
Description: The issue allows attackers to infect users with arbitrary JavaScript code that runs in the context of the "Numerix License Server Administration System Login" page (nlslogin.jsp) when they click on a malicious link or visit a website under the control of an attacker. This can be triggered by sending a specially crafted HTTP POST request to the nlslogin.jsp page. The vendor has been unresponsive, and as a result, there is no available solution. Users are advised to restrict access and monitor logs.
Recommendations: To mitigate the risk, restrict access to the nlslogin.jsp page and monitor logs for suspicious activity. Try to reach out to your contact person for the Numerix vendor and request a patch. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-50585

Affected Products

Numerix License Server