CVE-2024-37382

An issue discovered in import host feature in Ab Initio Metadata Hub and Authorization Gateway before 4.3.1.1 allows attackers to run arbitrary code via crafted modification of server configuration.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CISA-ADPADP
6.3 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 22%
VendorProductVersion
abinitioauthorization_gateway
𝑥
< 4.1.4.9
abinitioauthorization_gateway
4.1.5.10
abinitioauthorization_gateway
4.1.6.11
abinitioauthorization_gateway
4.2.1.6
abinitioauthorization_gateway
4.2.2.8
abinitioauthorization_gateway
4.2.3.4
abinitioauthorization_gateway
4.3.1.0
abinitiometadata_hub
𝑥
< 4.1.4.9
abinitiometadata_hub
4.1.5.10
abinitiometadata_hub
4.1.6.11
abinitiometadata_hub
4.2.1.6
abinitiometadata_hub
4.2.2.8
abinitiometadata_hub
4.2.3.4
abinitiometadata_hub
4.3.1.0
𝑥
= Vulnerable software versions