HomeProgressCVE-2024-6097

CVE-2024-6097

MEDIUM
5.3CVSS
Published: 2025-02-12
Updated: 2025-02-24
AI Analysis

Description

In Progress® Telerik® Reporting versions prior to 2025 Q1 (19.0.25.211), information disclosure is possible by a local threat actor through an absolute path vulnerability.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
network
Complexity
low
Privileges
none
User Action
none
Scope
unchanged
Confidentiality
low
Integrity
none
Availability
none
Weaknesses
CWE-36CWE-22

Metadata

Primary Vendor
PROGRESS
Published
2/12/2025
Last Modified
2/24/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

progress : telerik_reporting

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief