Vulnerability Description
NATO NCI ANET 3.4.1 allows Insecure Direct Object Reference via a modified ID field in a request for a private draft report (that belongs to an arbitrary user).
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ncia | Advisor Network | 3.4.1 |
Related Weaknesses (CWE)
References
- https://www.linkedin.com/pulse/idors-ncia-anet-v341-visionspace-technologies-hepExploitThird Party Advisory
- https://www.linkedin.com/pulse/idors-ncia-anet-v341-visionspace-technologies-hepExploitThird Party Advisory
FAQ
What is CVE-2024-38447?
CVE-2024-38447 is a vulnerability with a CVSS score of 8.1 (HIGH). NATO NCI ANET 3.4.1 allows Insecure Direct Object Reference via a modified ID field in a request for a private draft report (that belongs to an arbitrary user).
How severe is CVE-2024-38447?
CVE-2024-38447 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-38447?
Check the references section above for vendor advisories and patch information. Affected products include: Ncia Advisor Network.