SQL Injection Vulnerability in Polarion Products by Siemens
CVE-2024-51444

7.1HIGH

Key Information:

Vendor

Siemens

Vendor
CVE Published:
13 May 2025

What is CVE-2024-51444?

A vulnerability has been discovered in Polarion products, notably affecting all versions of Polarion V2310 and versions of Polarion V2404 prior to V2404.4. This security flaw emerges from inadequate validation of user inputs during database read operations, enabling an authenticated remote attacker to potentially exploit the weakness via an SQL injection attack. Such an attack could circumvent authorization controls and facilitate unauthorized access to sensitive data stored within the application's database.

Affected Version(s)

Polarion V2310 0

Polarion V2404 0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-51444 : SQL Injection Vulnerability in Polarion Products by Siemens