
Cloud Vulnerability DB
A community-led vulnerabilities database
An information disclosure vulnerability (CVE-2024-6097) was identified in Progress® Telerik® Reporting versions prior to 2025 Q1 (19.0.25.211). The vulnerability was discovered by Markus Wulftange with CODE WHITE GmbH and is classified as an absolute path traversal vulnerability (CWE-36) (Telerik Docs).
The vulnerability is classified as a medium severity issue with a CVSS score of 5.3. The security flaw specifically affects the Windows desktop standalone Report Designer component and does not impact the Reporting's processing engine or REST services (Telerik Docs).
The vulnerability could potentially lead to information disclosure when exploited by a local threat actor through an absolute path vulnerability (Telerik Docs).
Progress Telerik has addressed the issue by releasing version 2025 Q1 (19.0.25.211). Users running version 2024 Q4 (18.3.24.1218) or earlier are advised to upgrade to the latest version. Users can verify their current version either through the REST service's /api/reports/version/ endpoint or by checking PC Settings > Installed Apps > Telerik Reporting details (Telerik Docs).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."