CVE-2024-28765
published 2026-05-27CVE-2024-28765: IBM SDI 7.2.0.0 through 7.2.0.14 and IBM Security Directory Integrator 10.0.0.0 through 10.0.0.2 could allow a remote attacker to obtain sensitive information…
PriorityP426medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.39%
30.6th percentile
IBM SDI 7.2.0.0 through 7.2.0.14 and IBM Security Directory Integrator 10.0.0.0 through 10.0.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | sdi | 7.2.0.0 – 7.2.0.14 | — |
| ibm | security_directory_integrator | >= 10.0.0 < 10.0.0.3 | 10.0.0.3 |
| ibm | security_directory_integrator | 10.0.0.0 – 10.0.0.2 | — |
| ibm | security_directory_integrator | >= 7.2.0 < 7.2.0.15 | 7.2.0.15 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
IBM SDI/Security Directory Integrator information exposure (EUVD-2024-55599)
vuldb·2026-06-07·CVSS 5.3
CVE-2024-28765 [MEDIUM] IBM SDI/Security Directory Integrator information exposure (EUVD-2024-55599)
A vulnerability labeled as problematic has been found in IBM SDI and Security Directory Integrator. Impacted is an unknown function. The manipulation results in information exposure through error message.
This vulnerability is identified as CVE-2024-28765. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.
GHSA
GHSA-9922-6vmq-8fjg: IBM SDI 7
ghsa_unreviewed·2026-05-27
CVE-2024-28765 [MEDIUM] CWE-209 GHSA-9922-6vmq-8fjg: IBM SDI 7
IBM SDI 7.2.0.0 through 7.2.0.14 and IBM Security Directory Integrator 10.0.0.0 through 10.0.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-27
Published