Serviceware Processes 6.0 through 7.3 before 7.4 allows attackers without valid authentication to send a specially crafted HTTP request to a service endpoint resulting in remote code execution.
An attacker without valid authentication sends a specially crafted HTTP request directly to the service endpoint of the Serviceware Processes application. The vulnerability related to a missing required authentication mechanism (CWE-1394) allows the malicious request to be processed by the server. As a result, remote execution of arbitrary code in the context of the application or operating system is possible.
An attacker can remotely execute arbitrary code on the server without needing to possess an account in the system, which may lead to complete server takeover, data breach, data modification, or further lateral movement in the organization's network.
Serviceware Processes must be urgently updated to version 7.4 or newer. Detailed information about the patch is available at https://security.serviceware-se.com/CVE-2024-48956/. Until the update is applied, it is recommended to restrict network access to the application's service endpoints using a firewall or network access control mechanisms.
Serviceware Processes versions 6.0 through 7.3 (before version 7.4)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H