CRITICAL🇵🇱 Wersja polska

CVE-2024-8644

CVSS 9.3v4.0pub. 2024-09-27upd. 2026-06-02

Cleartext Storage of Sensitive Information in a Cookie vulnerability in Oceanic Software ValeApp allows Protocol Manipulation, : JSON Hijacking (aka JavaScript Hijacking). This issue affects ValeApp: before v2.0.0.

🤖 AI Analysis
How it works

The vulnerability results from improper storage of sensitive data in cookies without encryption (CWE-312, CWE-315). An attacker can exploit this flaw to manipulate the communication protocol (Protocol Manipulation) or conduct a JSON Hijacking attack (JavaScript Hijacking), which involves intercepting JSON responses returned by the application. Data in cookies is available in plain text, which facilitates its reading and modification by unauthorized entities.

Impact

An attacker can intercept sensitive information from cookies, including session or authentication data, and then use it to gain unauthorized access to the application or its resources. It is also possible to manipulate data transmitted between the client and server.

Mitigation & patch

The ValeApp application should be updated to version v2.0.0 or later, in which the issue has been eliminated. Detailed information is available in the vendor's references and in the USOM security bulletin (TR-24-1562).

Who is affected

Oceanic Software ValeApp in all versions prior to v2.0.0.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Oceanicsoft Valeapp

    APP
    Oceanicsoft
    < 2.0.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-8643CRITICAL9.3PL ✓same product

Session Fixation w Oceanicsoft ValeApp umożliwia przejęcie sesji

CVE-2024-8607HIGH8.7same product

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oceanic ...

CVE-2024-8608HIGH7.2same product

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in O...

CVE-2024-8609HIGH8.8same product

Insertion of Sensitive Information into Log File vulnerability in Oceanic Software ValeApp allows Query System...