CVE-2024-31898Authorization Bypass Through User-Controlled Key in IBM Infosphere Information Server

Severity
5.4MEDIUMNVD
EPSS
0.0%
top 92.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 30

Description

IBM InfoSphere Information Server 11.7 could allow an authenticated user to read or modify sensitive information by bypassing authentication using insecure direct object references. IBM X-Force ID: 288182.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.5

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-cq47-mvqf-ggfh: IBM InfoSphere Information Server 112024-06-30
CVEList
IBM InfoSphere Information Server data modification2024-06-30
CVE-2024-31898 — IBM vulnerability | cvebase