PT-2024-37600 · Yordam Information Technology · Yordam Information Technology Mobile Library Application

Published

2024-09-18

·

Updated

2025-10-14

·

CVE-2024-6406

CVSS v4.0

8.5

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:H/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Yordam Information Technology Mobile Library Application versions prior to 5.0
Description The issue allows exposure of sensitive information to an unauthorized actor, enabling the retrieval of embedded confidential information.
Recommendations For versions prior to 5.0, update to version 5.0 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive data within the application until a patch is available.

Fix

Missing Authorization

Missing Authentication

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2024-6406

Affected Products

Yordam Information Technology Mobile Library Application