CVE Vulnerabilities

CVE-2024-37999

Improper Ownership Management

Published: Jul 08, 2024 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A vulnerability has been identified in Medicalis Workflow Orchestrator (All versions). The affected application executes as a trusted account with high privileges and network access. This could allow an authenticated local attacker to escalate privileges.

Weakness

The product assigns the wrong ownership, or does not properly verify the ownership, of an object or resource.

Affected Software

NameVendorStart VersionEnd Version
Medicalis_workflow_orchestratorSiemens**

Potential Mitigations

References