CVE-2024-51444: Siemens Polarion Alm
Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.
A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.4). The application insufficiently validates user input for database read queries. This could allow an authenticated remote attacker to conduct an SQL injection attack that bypasses authorization controls and allows to download any data from the application's database.
Affected products
- Siemens Polarion Alm: from 2404.0, before 2404.4 (fixed in 2404.4); version 2310.0 only
Published 2025-05-13. Last modified 2026-06-17.