CVE-2024-9984: Ragic Enterprise Cloud Database

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Enterprise Cloud Database from Ragic does not authenticate access to specific functionality, allowing unauthenticated remote attackers to use this functionality to obtain any user's session cookie.

Affected products

  • Ragic Enterprise Cloud Database: before 2024-08-08 (fixed in 2024-08-08)

Published 2024-10-15. Last modified 2026-06-17.