Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-37162 | An authenticated attacker can exploit an improper authorization vulnerability in Azure Web Apps to elevate privileges over a network. |
Wed, 25 Feb 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:microsoft:azure_web_apps:*:*:*:*:*:*:*:* |
Tue, 17 Sep 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-noinfo |
Tue, 10 Sep 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Sep 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated attacker can exploit an improper authorization vulnerability in Azure Web Apps to elevate privileges over a network. | |
| Title | Azure Web Apps Elevation of Privilege Vulnerability | |
| First Time appeared |
Microsoft
Microsoft azure Web Apps |
|
| Weaknesses | CWE-20 | |
| CPEs | cpe:2.3:a:microsoft:azure_web_apps:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Microsoft
Microsoft azure Web Apps |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2024-12-31T23:03:25.824Z
Reserved: 2024-06-11T22:36:08.217Z
Link: CVE-2024-38194
Updated: 2024-09-10T18:17:30.792Z
Status : Analyzed
Published: 2024-09-10T17:15:24.200
Modified: 2024-09-17T17:02:40.553
Link: CVE-2024-38194
No data.
OpenCVE Enrichment
No data.
EUVD