Unvalidated Server Names Expose Sensitive Information in IBM Storage Defender 2.0.0-2.0.7
CVE-2024-38324
6.5MEDIUM
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 25 September 2024
What is CVE-2024-38324?
IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI does not validate server name during registration and unregistration operations which could expose sensitive information to an attacker with access to the system.
Affected Version(s)
Storage Defender - Resiliency Service 2.0.0 <= 2.0.7