CVE-2024-0396

In Progress MOVEit Transfer versions released before 2022.0.10 (14.0.10), 2022.1.11 (14.1.11), 2023.0.8 (15.0.8), 2023.1.3 (15.1.3), an input validation issue was discovered. An authenticated user can manipulate a parameter in an HTTPS transaction. The modified transaction could lead to computational errors within MOVEit Transfer and potentially result in a denial of service.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*
cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*
cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*
cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*

History

29 Jan 2024, 15:22

Type Values Removed Values Added
CPE cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*
First Time Progress
Progress moveit Transfer
CWE NVD-CWE-noinfo
Summary
  • (es) En las versiones de Progress MOVEit Transfer lanzadas antes de 2022.0.10 (14.0.10), 2022.1.11 (14.1.11), 2023.0.8 (15.0.8), 2023.1.3 (15.1.3), se descubrió un problema de validación de entrada. Un usuario autenticado puede manipular un parámetro en una transacción HTTPS. La transacción modificada podría provocar errores computacionales dentro de MOVEit Transfer y potencialmente resultar en una denegación de servicio.
References () https://community.progress.com/s/article/MOVEit-Transfer-Service-Pack-January-2024 - () https://community.progress.com/s/article/MOVEit-Transfer-Service-Pack-January-2024 - Vendor Advisory
References () https://www.progress.com/moveit - () https://www.progress.com/moveit - Product

17 Jan 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-17 16:15

Updated : 2024-01-29 15:22


NVD link : CVE-2024-0396

Mitre link : CVE-2024-0396

CVE.ORG link : CVE-2024-0396


JSON object : View

Products Affected

progress

  • moveit_transfer
CWE
NVD-CWE-noinfo CWE-20

Improper Input Validation