VYPR
Unrated severityNVD Advisory· Published May 13, 2025· Updated May 13, 2025

CVE-2024-51444

CVE-2024-51444

Description

A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.4). The application insufficiently validates user input for database read queries. This could allow an authenticated remote attacker to conduct an SQL injection attack that bypasses authorization controls and allows to download any data from the application's database.

Affected products

3
  • Siemens Foundation/Polarionllm-fuzzy3 versions
    V2310 all versions, V2404 < V2404.4+ 2 more
    • (no CPE)range: V2310 all versions, V2404 < V2404.4
    • (no CPE)range: 0
    • (no CPE)range: 0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.