Skip to main content

Modification of Assumed-Immutable Data (MAID)

CVE-2024-51462

Severity Medium
Score 4/10

Summary

IBM QRadar WinCollect Agent 10.0.0 through 10.1.12 could allow a remote attacker to inject XML data into parameter values due to improper input validation of assumed immutable data.

  • LOW
  • LOCAL
  • LOW
  • UNCHANGED
  • NONE
  • NONE
  • NONE
  • NONE

CWE-471 - Modification of Assumed-Immutable Data (MAID)

The software does not properly protect an assumed-immutable element from being modified by an attacker.

References

Advisory Timeline

  • Published