{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-21T18:40:29.456","vulnerabilities":[{"cve":{"id":"CVE-2024-8015","sourceIdentifier":"security@progress.com","published":"2024-10-09T15:15:17.097","lastModified":"2026-06-17T08:21:41.557","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"In Progress Telerik Report Server versions prior to 2024 Q3 (10.2.24.924), a remote code execution attack is possible through object injection via an insecure type resolution vulnerability."},{"lang":"es","value":"En las versiones de Telerik Report Server anteriores al tercer trimestre de 2024 (10.2.24.924), es posible un ataque de ejecución remota de código mediante la inyección de objetos mediante una vulnerabilidad de resolución de tipos insegura."}],"affected":[{"source":"security@progress.com","affectedData":[{"vendor":"Progress Software","product":"Telerik Reporting","defaultStatus":"unaffected","versions":[{"version":"1.0.0.0","lessThan":"10.2.24.924","versionType":"custom","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"progress_software","product":"telerik_reporting","defaultStatus":"unknown","cpes":["cpe:2.3:a:progress_software:telerik_reporting:*:*:*:*:*:*:*:*"],"versions":[{"version":"1.0.0.0","lessThan":"10.2.24.924","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@progress.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.3,"impactScore":6.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-10-09T16:04:21.526771Z","id":"CVE-2024-8015","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@progress.com","type":"Secondary","description":[{"lang":"en","value":"CWE-470"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:progress:telerik_report_server:*:*:*:*:*:*:*:*","versionEndExcluding":"10.2.24.924","matchCriteriaId":"6F140E0F-FA02-42EA-9F33-928B6BE6D7B6"}]}]}],"references":[{"url":"https://docs.telerik.com/report-server/knowledge-base/insecure-type-resolution-cve-2024-8015","source":"security@progress.com","tags":["Vendor Advisory"]}]}}]}