Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
This issue is fixed in Cortex XSOAR 6.12.0 (Build 1271551), and all later Cortex XSOAR versions.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-49962 | A vulnerability in Cortex XSOAR allows the disclosure of incident data to users who do not have the privilege to view the data. |
| Link | Providers |
|---|---|
| https://security.paloaltonetworks.com/CVE-2024-9470 |
|
Fri, 18 Oct 2024 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Paloaltonetworks
Paloaltonetworks cortex Xsoar |
|
| CPEs | cpe:2.3:a:paloaltonetworks:cortex_xsoar:6.12.0:-:*:*:*:*:*:* cpe:2.3:a:paloaltonetworks:cortex_xsoar:6.12.0:B493375:*:*:*:*:*:* cpe:2.3:a:paloaltonetworks:cortex_xsoar:6.12.0:B661643:*:*:*:*:*:* cpe:2.3:a:paloaltonetworks:cortex_xsoar:6.12.0:B857430:*:*:*:*:*:* |
|
| Vendors & Products |
Paloaltonetworks
Paloaltonetworks cortex Xsoar |
Fri, 11 Oct 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 09 Oct 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in Cortex XSOAR allows the disclosure of incident data to users who do not have the privilege to view the data. | |
| Title | Cortex XSOAR: Information Disclosure Vulnerability | |
| Weaknesses | CWE-497 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: palo_alto
Published:
Updated: 2024-10-18T11:56:57.614Z
Reserved: 2024-10-03T11:35:17.024Z
Link: CVE-2024-9470
Updated: 2024-10-10T17:40:35.691Z
Status : Deferred
Published: 2024-10-09T17:15:20.907
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-9470
No data.
OpenCVE Enrichment
No data.
EUVD