PT-2025-2938 · Teradata · Teradata Vantage Editor
Published
2025-01-17
·
Updated
2025-01-17
·
CVE-2024-52870
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Teradata Vantage Editor version 1.0.1
Description
The issue concerns unintended functionality in the software, including the presence of Chromium Developer Tools, which can allow a client user to access arbitrary remote websites. This can potentially lead to unauthorized access to external resources.
Recommendations
For Teradata Vantage Editor version 1.0.1, consider restricting access to the Chromium Developer Tools as a temporary workaround until a patch is available. Additionally, limit the ability of client users to access arbitrary remote websites through the editor to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Teradata Vantage Editor