CVE-2024-37533Exposure of Private Personal Information to an Unauthorized Actor in IBM Infosphere Information Server

Severity
4.6MEDIUMNVD
CNA2.4
EPSS
0.1%
top 83.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 24

Description

IBM InfoSphere Information Server 11.7 could disclose sensitive user information to another user with physical access to the machine. IBM X-Force ID: 294727.

CVSS vector

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 0.9 | Impact: 3.6

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
IBM InfoSphere Information Server information disclosure2024-07-24
GHSA
GHSA-6r69-3xcf-x5gg: IBM InfoSphere Information Server 112024-07-24

📋Vendor Advisories

3
Oracle
Oracle Oracle Communications Applications Risk Matrix: JCA Adaptor (Apache Commons Net) — CVE-2021-375332024-07-15
Oracle
Oracle Oracle Communications Applications Risk Matrix: General (Apache Commons Net) — CVE-2021-375332024-04-15
Oracle
Oracle Oracle Communications Applications Risk Matrix: Order and Service Management (Apache Commons Net) — CVE-2021-375332024-01-15
CVE-2024-37533 — IBM vulnerability | cvebase