Vulnerability in ESM 11.6.10 Allows Unauthorized Access to Internal API Endpoints
CVE-2024-11481
8.2HIGH
What is CVE-2024-11481?
A vulnerability exists in ESM version 11.6.10, permitting unauthorized access to the internal Snowservice API. This flaw stems from improper handling of path traversal, which can lead to insecure forwarding to an AJP backend without sufficient validation. Additionally, the vulnerability is characterized by a lack of authentication mechanisms for critical internal API endpoints, exposing systems to potential exploitation.
Affected Version(s)
Trellix Enterprise Security Manager (ESM) Windows 11.6.12