IBM i SST User Enumeration Vulnerability

CVE-2024-31878
5.3MEDIUM

Key Information

Vendor
IBM
Status
I
Vendor
Published:
7 June 2024

Summary

IBM i 7.2, 7.3, 7.4, and 7.5 Service Tools Server (SST) is vulnerable to SST user enumeration by a remote attacker. This vulnerability can be used by a malicious actor to gather information about SST users that can be targeted in further attacks. IBM X-Force ID: 287538.

Affected Version(s)

i = 7.2, 7.3, 7.4, 7.5

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
LOW
Integrity:
NONE
Availability:
NONE
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database
.