SQL Injection Vulnerability in IBM Engineering Lifecycle Optimization - Publishing
CVE-2024-41767
7.3HIGH
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 4 January 2025
What is CVE-2024-41767?
The SQL injection vulnerability in IBM Engineering Lifecycle Optimization - Publishing affects versions 7.0.2 and 7.0.3. This security issue arises when a remote attacker exploits weaknesses in the application by sending specially crafted SQL statements. By doing so, the attacker may gain unauthorized access to the back-end database, potentially allowing them to view, add, modify, or delete critical information. Organizations using these versions are advised to apply the latest security patches and adopt best practices to mitigate the risks associated with SQL injection attacks.
Affected Version(s)
Engineering Lifecycle Optimization Publishing 7.0.2, 7.0.3