Improper Access Control in HCL Leap Affects Application Importing
CVE-2024-30148
4.1MEDIUM
What is CVE-2024-30148?
An improper access control vulnerability in HCL Leap enables certain administrative users to import applications directly from the server's filesystem, potentially exposing sensitive data or allowing unauthorized manipulation of applications. This flaw highlights the need for strict access permissions to safeguard against unauthorized actions within the application environment.
Affected Version(s)
HCL Leap < 9.3.8