CVE-2024-52870 Details
Description
Teradata Vantage Editor 1.0.1 is mostly intended for SQL database access and docs.teradata.com access, but provides unintended functionality (including Chromium Developer Tools) that can result in a client user accessing arbitrary remote websites.
A vulnerability in Teradata Vantage Editor Desktop version 1.0.1 and earlier allows users to bypass intended restrictions and access arbitrary remote websites. This issue arises from the application's unintentional exposure of Chromium Developer Tools, which can be used to manipulate the embedded browser's behavior. While Vantage Editor is primarily designed for SQL database access, the vulnerability could be exploited by convincing a user to execute JavaScript code in the developer console, effectively turning the application into an unrestricted web browser. This could lead to unauthorized access to websites or, potentially, to other security exploits, such as injecting malicious code into SQL query results or phishing for Teradata database credentials.
Users are advised to upgrade to Teradata Vantage Editor Desktop version 1.1.0 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 17, 2025CISA-ADP
Assessed Jan 17, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://chrismanson.com/CVE/cve-2024-52870.html | [email protected] | AdvisoryExploitRemedy |
| https://www.teradata.com/trust-security-center/data-security | [email protected] | Vendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-909 | Missing Initialization of Resource | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Teradata Vantage Editor Desktop | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 17, 2025 | CVE Modified | CISA-ADP |
| Jan 17, 2025 | New CVE Received | [email protected] |
Volerion