Remote Information Exposure Vulnerability in IBM Engineering Insights
CVE-2024-39725

5.3MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
25 December 2024

Summary

IBM Engineering Lifecycle Optimization - Engineering Insights versions 7.0.2 and 7.0.3 are impacted by a vulnerability that permits remote attackers to gain sensitive information. This risk arises when detailed technical error messages are outputted in the browser, potentially revealing crucial data that may be exploited to conduct further attacks on the system. Organizations utilizing affected versions should take immediate action to mitigate risks associated with unauthorized information disclosure.

Affected Version(s)

Engineering Insights 7.0.2, 7.0.3

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.