Code Injection in nest - CVE-2024-29409
Published: June 26, 2025
Vulnerability identifier: #VU111977
CSH Severity: Low
CVSS v4 BT: 1.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2024-29409
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation. A remote user can send a specially crafted request and execute arbitrary code via the Content-Type header on the target system.
Affected software
nest
IBM Concert Software
Netcool Operations Insight
IBM Cloud Pak for Watson AIOps
IBM Concert Software
Netcool Operations Insight
IBM Cloud Pak for Watson AIOps
How to mitigate CVE-2024-29409
Install updates from vendor's website.
nest - update to 10.3.3
IBM Concert Software - update to 2.0.0
Netcool Operations Insight - update to 1.6.15
IBM Cloud Pak for Watson AIOps - update to 4.10.0
IBM Concert Software - update to 2.0.0
Netcool Operations Insight - update to 1.6.15
IBM Cloud Pak for Watson AIOps - update to 4.10.0