CVE-2024-42464
CVE-2024-42464 is a medium-severity vulnerability in Upkeeper Upkeeper Manager with a CVSS 3.x base score of 6.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-639.
Key facts
- Severity: Medium (CVSS 3.x base score 6.5)
- CVSS v4: 7.6
- EPSS exploit prediction: 0% (24th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2024-39631
- Weakness: CWE-639
- Affected product: Upkeeper Upkeeper Manager
- Published:
- Last modified:
Description
Authorization Bypass Through User-Controlled Key vulnerability in upKeeper Solutions product upKeeper Manager allows Utilizing REST's Trust in the System Resource to Obtain Sensitive Data.This issue affects upKeeper Manager: through 5.1.9.
Frequently asked questions
- What is CVE-2024-42464?
- Authorization Bypass Through User-Controlled Key vulnerability in upKeeper Solutions product upKeeper Manager allows Utilizing REST's Trust in the System Resource to Obtain Sensitive Data.This issue affects upKeeper Manager: through 5.1.9.
- How severe is CVE-2024-42464?
- CVE-2024-42464 has a CVSS 3.x base score of 6.5, rated medium severity. It is exploitable over network with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is high, integrity none, and availability none.
- Is CVE-2024-42464 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (24th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2024-42464?
- CVE-2024-42464 affects Upkeeper Upkeeper Manager. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2024-42464?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2024-42464 have an EU (EUVD) identifier?
- Yes. CVE-2024-42464 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2024-39631.
- When was CVE-2024-42464 published?
- CVE-2024-42464 was published on 2024-08-16 and last updated on 2026-06-17.
References
- https://support.upkeeper.se/hc/en-us/articles/15432275702044-CVE-2024-42464-Leak-of-user-Information
Affected products (1)
- cpe:2.3:a:upkeeper:upkeeper_manager:*:*:*:*:*:*:*:*
More vulnerabilities in Upkeeper Upkeeper Manager
- CVE-2024-42466 — Critical (CVSS 9.8): Improper Restriction of Excessive Authentication Attempts vulnerability in upKeeper Solutions product upKeeper Manager…
- CVE-2024-42465 — Critical (CVSS 9.8): Improper Restriction of Excessive Authentication Attempts vulnerability in upKeeper Solutions product upKeeper Manager…
- CVE-2024-42462 — Critical (CVSS 9.8): Improper Authentication vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Bypass.This…
- CVE-2025-11446 — Medium (CVSS 6.5): Insertion of Sensitive Information into Log File vulnerability in upKeeper Solutions upKeeper Manager allows Use of…
- CVE-2025-8663 — Medium (CVSS 6.5): Insertion of Sensitive Information into Log File vulnerability in upKeeper Solutions upKeeper Manager allows Use of…
- CVE-2024-42463 — Medium (CVSS 6.5): Authorization Bypass Through User-Controlled Key vulnerability in upKeeper Solutions product upKeeper Manager allows…
All CVEs affecting Upkeeper Upkeeper Manager →
Other CWE-639 (Authorization Bypass Through User-Controlled Key (IDOR)) vulnerabilities
- CVE-2025-40805 — Critical (CVSS 10.0): Affected devices do not properly enforce user authentication on specific API endpoints. This could facilitate an…
- CVE-2024-45032 — Critical (CVSS 10.0): A vulnerability has been identified in Industrial Edge Management Pro (All versions < V1.9.5), Industrial Edge…
- CVE-2026-62283 — Critical (CVSS 9.9): Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Nezha versions 1.14.13…
- CVE-2026-73656 — Critical (CVSS 9.9): Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST…
- CVE-2026-48765 — Critical (CVSS 9.9): TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege read collaborator to extract a…
- CVE-2026-67622 — Critical (CVSS 9.9): Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration…
Browse all CWE-639 (Authorization Bypass Through User-Controlled Key (IDOR)) vulnerabilities →