CVE-2024-47085 - Oracle LD DP Back Office Information Disclosure Vulnerability

4 weeks ago 21
ARTICLE AD BOX
CVE ID : CVE-2024-47085
Published : Sept. 19, 2024, 6:15 a.m. | 24 minutes ago
Description : This vulnerability exists in LD DP Back Office due to improper validation of certain parameters “cCdslClicentcode” and “cLdClientCode” in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating parameters in the API request body leading to exposure of sensitive information belonging to other users.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Read Entire Article