Remote Information Exposure Vulnerability in IBM Engineering Insights
CVE-2024-39725
5.3MEDIUM
Summary
IBM Engineering Lifecycle Optimization - Engineering Insights versions 7.0.2 and 7.0.3 are impacted by a vulnerability that permits remote attackers to gain sensitive information. This risk arises when detailed technical error messages are outputted in the browser, potentially revealing crucial data that may be exploited to conduct further attacks on the system. Organizations utilizing affected versions should take immediate action to mitigate risks associated with unauthorized information disclosure.
Affected Version(s)
Engineering Insights 7.0.2, 7.0.3
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database