OPS/MVS 14.0 - MTCA Upgrade Spring Security from 5.7.12 to 5.7.13 - Vulnerability CVE-2024-38821
25196
03 December 2024
03 December 2024
OPEN
CRITICAL
9.1
CVE-2024-38821
Broadcom Mainframe Software is alerting customers to a vulnerability in OPS/MVS.
| Product Name | OPS/MVS 14.0 MTC-A |
| Affected component(s) | FMID:CCLXE01 Upgrade Spring Security from 5.7.12 to 5.7.13 |
| Version PE was Introduced | FMID in Error: CCLXE01 Published Date: 08-10-2020 |
| Severity | CRITICAL |
| CVE | CVE-2024-38821 |
| CVSS Score | Base:9.1 Temporal:7.9 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/ |
| CVSS Description | This vulnerability is remotely exploitable. It only requires that the vulnerable system be network connected. Exploitation of this vulnerability will have repeatable results and success. There are no specialized access conditions or extenuating circumstances to make the exploitation complex. This vulnerability can be carried out by an unauthorized attacker. Exploitation of the vulnerability does not require any user interaction. This vulnerability will not cause an escalation of privilege. There is a total loss of confidentiality, integrity. There is no impact on availability. No exploit code is available, or an exploit is completely theoretical. |
| Solution | LU15235 |
| Platform(s) | z/OS |