CVE-2024-2097

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
27/03/2024
Last modified:
15/04/2026

Description

An authenticated malicious client can send a special LINQ query<br /> to execute arbitrary code remotely (RCE) on the SCM server<br /> from List control, and execute the arbitrary code on the same<br /> system where SCMArchivedEventViewerTool is installed in the<br /> case of SCM Tools.