CVE-2024-33647: Siemens Polarion Alm
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
A vulnerability has been identified in Polarion ALM (All versions < V2404.0). The Apache Lucene based query engine in the affected application lacks proper access controls. This could allow an authenticated user to query items beyond the user's allowed projects.
Affected products
- Siemens Polarion Alm: before V2404.0 (fixed in V2404.0)
Published 2024-05-14. Last modified 2026-06-17.