CVE-2024-8015

In Progress Telerik Report Server versions prior to 2024 Q3 (10.2.24.924), a remote code execution attack is possible through object injection via an insecure type resolution vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:progress:telerik_report_server:*:*:*:*:*:*:*:*

History

15 Oct 2024, 14:55

Type Values Removed Values Added
CPE cpe:2.3:a:progress:telerik_report_server:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : 9.1
v2 : unknown
v3 : 7.2
First Time Progress
Progress telerik Report Server
References () https://docs.telerik.com/report-server/knowledge-base/insecure-type-resolution-cve-2024-8015 - () https://docs.telerik.com/report-server/knowledge-base/insecure-type-resolution-cve-2024-8015 - Vendor Advisory

10 Oct 2024, 12:51

Type Values Removed Values Added
Summary
  • (es) En las versiones de Telerik Report Server anteriores al tercer trimestre de 2024 (10.2.24.924), es posible un ataque de ejecución remota de código mediante la inyección de objetos mediante una vulnerabilidad de resolución de tipos insegura.

09 Oct 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-09 15:15

Updated : 2024-10-15 14:55


NVD link : CVE-2024-8015

Mitre link : CVE-2024-8015

CVE.ORG link : CVE-2024-8015


JSON object : View

Products Affected

progress

  • telerik_report_server
CWE
CWE-470

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')