CVE-2024-52359
IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 could allow an authenticated user to perform unauthorized actions that should be reserved to administrator used due to improper access controls.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- EPSS probability
- 0.31%
- CWE
- CWE-286
- Published
- 2024-11-19
- Last modified
- 2026-03-13
Affected products
- IBM Concert Software
Weakness type
Related vulnerabilities
- CVE-2026-56428 — The SSH service on BSH ELP (Electronic Platform) modules contains a platform-specific vulnerability...
- CVE-2026-60135 — Weintek cMT3092X Incorrect User Management
- CVE-2026-35638 — OpenClaw < 2026.3.22 - Privilege Escalation via Self-Declared Scopes in Trusted-Proxy Control UI
- CVE-2025-64725 — Weblate has improper validation upon invitation acceptance
- CVE-2025-59943 — phpMyFAQ duplicate email registration allows multiple accounts with the same email
- CVE-2025-7972 — Rockwell Automation FactoryTalk® Linx Network Browser Security Bypass Vulnerability
- CVE-2024-48853 — Authenticated Escalation to guest to root
- CVE-2024-46671 — An Incorrect User Management vulnerability [CWE-286] in FortiWeb version 7.6.2 and below, version...