CVE-2024-3995 LOW

CVE-2024-3995: Command Injection in Helix ALM

Vendor Perforce
Product Helix ALM
Weakness CWE-94 · Code injection
Published June 28, 2024
Last update August 1, 2024

CVSS base score

2.0/10
Attack vector Local
Attack complexity High
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

What the vulnerability does

01Description

In Helix ALM versions prior to 2024.2.0, a local command injection was identified. Reported by Bryan Riggins.

Key dates

02Disclosure timeline

June 28, 2024 CVE published
August 1, 2024 Record updated