VDB

CVE-2024-51444

CVE-2024-51444 PUBLISHED CVSS 6.5 MEDIUM

A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.4). The application insufficiently validates user input for database read queries. This could allow an authenticated remote attacker to conduct an SQL injection attack that bypasses authorization controls and allows to download any data from the application's database.

EPSS 0.54% · 43.3th percentile

Risk Scores

CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.54%
43.3th percentile

Affected Products

VendorProductVersions
siemenspolarion_alm2404.0, 2310.0, 2404.0
SiemensPolarion V23100, 0
SiemensPolarion V24040, 0

Timeline

  • May 13, 2025 EPSS Score
  • May 13, 2025 Coalition ESS Score
  • May 13, 2025 CVE Published
  • May 15, 2025 PoC Published
  • May 25, 2025 EPSS Score
  • Jun 6, 2025 EPSS Score
  • Jun 18, 2025 EPSS Score
  • Jun 30, 2025 EPSS Score
  • Jul 12, 2025 EPSS Score
  • Jul 24, 2025 EPSS Score
  • Aug 5, 2025 EPSS Score
  • Aug 16, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›