An Insecure Direct Object Reference (IDOR) in PTC ThingWorx v9.5.0 allows attackers to view sensitive information, including PII, regardless of access level.
References
Link | Resource |
---|---|
https://pastebin.com/9dc4LYGA | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2024-08-27 16:15
Updated : 2025-03-25 17:15
NVD link : CVE-2024-40395
Mitre link : CVE-2024-40395
CVE.ORG link : CVE-2024-40395
JSON object : View
Products Affected
ptc
- thingworx
CWE
CWE-639
Authorization Bypass Through User-Controlled Key