CVE-2024-37382

EUVD-2024-36624
An issue discovered in import host feature in Ab Initio Metadata Hub and Authorization Gateway before 4.3.1.1 allows attackers to run arbitrary code via crafted modification of server configuration.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
6.3 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 42%
Affected Products (NVD)
VendorProductVersion
abinitioauthorization_gateway
𝑥
< 4.1.4.9
abinitioauthorization_gateway
4.1.5.10
abinitioauthorization_gateway
4.1.6.11
abinitioauthorization_gateway
4.2.1.6
abinitioauthorization_gateway
4.2.2.8
abinitioauthorization_gateway
4.2.3.4
abinitioauthorization_gateway
4.3.1.0
abinitiometadata_hub
𝑥
< 4.1.4.9
abinitiometadata_hub
4.1.5.10
abinitiometadata_hub
4.1.6.11
abinitiometadata_hub
4.2.1.6
abinitiometadata_hub
4.2.2.8
abinitiometadata_hub
4.2.3.4
abinitiometadata_hub
4.3.1.0
𝑥
= Vulnerable software versions