3DEXPERIENCE Vulnerable to OS Command Injection
CVE-2024-1624
What is CVE-2024-1624?
The vulnerability presents an OS Command Injection issue within the documentation server of certain Dassault Systèmes products. This flaw exists across multiple versions of the 3DEXPERIENCE platform, SIMULIA Abaqus, SIMULIA Isight, and CATIA Composer. An attacker could craft a malicious HTTP request to execute arbitrary commands on the system, potentially compromising the integrity and security of the affected applications. The impact of such exploitation emphasizes the importance of timely patches and security measures for organizations utilizing these solutions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Documentation server Release 3DEXPERIENCE R2022x Golden
Documentation server Release 3DEXPERIENCE R2023x Golden
Documentation server Release 3DEXPERIENCE R2024x Golden
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
