CVE-2024-39669
Severity CVSS v4.0:
Pending analysis
Type:
CWE-94
Code Injection
Publication date:
27/06/2024
Last modified:
03/07/2024
Description
In the Console in Soffid IAM before 3.5.39, necessary checks were not applied to some Java objects. A malicious agent could possibly execute arbitrary code in the Sync Server and compromise security.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL



