CVE-2024-2097
Severity CVSS v4.0:
Pending analysis
Type:
CWE-94
Code Injection
Publication date:
27/03/2024
Last modified:
15/04/2026
Description
An authenticated malicious client can send a special LINQ query<br />
to execute arbitrary code remotely (RCE) on the SCM server<br />
from List control, and execute the arbitrary code on the same<br />
system where SCMArchivedEventViewerTool is installed in the<br />
case of SCM Tools.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH



