4 CVE-2024-51462

 

IBM QRadar WinCollect Agent 10.0.0 through 10.1.12 could allow a remote attacker to inject XML data into parameter values due to improper input validation of assumed immutable data.
https://nvd.nist.gov/vuln/detail/CVE-2024-51462

Categories

CWE-471 : Modification of Assumed-Immutable Data (MAID)
This occurs when a particular input is critical enough to the functioning of the application that it should not be modifiable at all, but it is. Certain resources are often assumed to be immutable when they are not, such as hidden form fields in web applications, cookies, and reverse DNS lookups.

References


 

CPE

cpe start end


REMEDIATION




EXPLOITS


Exploit-db.com

id description date
No known exploits

POC Github

Url
No known exploits

Other Nist (github, ...)

Url
No known exploits


CAPEC


Common Attack Pattern Enumerations and Classifications

id description severity
384 Application API Message Manipulation via Man-in-the-Middle
Low
385 Transaction or Event Tampering via Application API Manipulation
Medium
386 Application API Navigation Remapping
Medium
387 Navigation Remapping To Propagate Malicious Content
Medium
388 Application API Button Hijacking
Medium