Information Disclosure Vulnerability in IBM Security Directory Integrator
CVE-2024-28765

5.3MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
27 May 2026

What is CVE-2024-28765?

An information disclosure vulnerability exists in IBM Security Directory Integrator and IBM SDI versions 7.2.0.0 through 7.2.0.14 and 10.0.0.0 through 10.0.0.2. This issue occurs when the application displays detailed technical error messages in the browser, potentially allowing a remote attacker to harvest sensitive information. The exposed data could be leveraged for further malicious activities against the affected system.

Affected Version(s)

SDI 7.2.0.0 <= 7.2.0.14

Security Directory Integrator 10.0.0.0 <= 10.0.0.2

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.