VDB
CVE-2024-38807
CVE-2024-38807
PUBLISHED
Es besteht eine Schwachstelle in VMware Tanzu Spring Boot. Dieser Fehler besteht in der Komponente spring-boot-loader aufgrund einer Signaturfälschung, die es ermöglicht, Inhalte so aussehen zu lassen, als seien sie von einem anderen Benutzer signiert worden. Ein lokaler Angreifer kann diese Schwachstelle ausnutzen, um Sicherheitsmaßnahmen zu umgehen.
EPSS 0.04% · 11.1th percentile
Risk Scores
EPSS Score
0.04%
11.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Oracle Communications 15.0.0.0.0 | |
| Oracle | Oracle Communications 47.0.0.0.0 | |
| Oracle | Oracle Communications Applications <=6.0.5 | |
| Oracle | Oracle Communications Applications 7.5.0 | |
| Oracle | Oracle Communications Applications <=15.0.0.1 | |
| Oracle | Oracle Communications <=24.2.2 | |
| Oracle | Oracle Communications Applications 7.4.0 | |
| Oracle | Oracle Communications <=9.1.1.9 | |
| Oracle | Oracle Communications Applications 8.0.0.3 | |
| VMware Tanzu | VMware Tanzu Spring Boot <3.2.9 | |
| Oracle | Oracle Communications 23.4.0 | |
| Oracle | Oracle Communications 23.4.4 | |
| Oracle | Oracle Communications 24.2.3 | |
| Oracle | Oracle Communications 8.2.3.0.0 | |
| Oracle | Oracle Communications 15.0 | |
| Oracle | Oracle Communications Applications 7.4.1 | |
| Oracle | Oracle Communications 24.2.0 | |
| Oracle | Oracle Communications 9.2.0 | |
| VMware Tanzu | VMware Tanzu Spring Boot <3.1.13 | |
| Oracle | Oracle Communications 8.0 |
…and 30 more
Timeline
- Aug 22, 2024 CVE Published
- Aug 24, 2024 EPSS Score
- Sep 13, 2024 EPSS Score
- Oct 4, 2024 EPSS Score
- Oct 4, 2024 Coalition ESS Score
- Oct 24, 2024 EPSS Score
- Nov 14, 2024 EPSS Score
- Dec 5, 2024 EPSS Score
- Dec 25, 2024 EPSS Score
- Jan 15, 2025 EPSS Score
- Jan 19, 2025 CVE Updated
- Feb 4, 2025 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1916.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-1916 advisory
- https://spring.io/blog/2024/08/23/spring-boot-releases-fix-for-cve-2024-38807 advisory
- https://spring.io/security/cve-2024-38807 advisory
- https://security.netapp.com/advisory/ntap-20250117-0006/ advisory
- https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-0135.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-0135 advisory
- https://www.oracle.com/security-alerts/cpujan2025.html#AppendixCAGBU advisory
- https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-0148.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-0148 advisory
- https://www.oracle.com/security-alerts/cpujan2025.html#AppendixCGBU advisory