CVE-2024-38322

CWE-204CWE-2033 documents3 sources
Severity
7.5HIGH
EPSS
0.2%
top 63.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 28
Latest updateJun 29

Description

IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.4 agent username and password error response discrepancy exposes product to brute force enumeration. IBM X-Force ID: 294869.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.6 | Impact: 3.6

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-gv23-j6x4-4x4x: IBM Storage Defender - Resiliency Service 22024-06-29
CVEList
IBM Storage Defender information disclosure2024-06-28
CVE-2024-38322 (HIGH CVSS 7.5) | IBM Storage Defender - Resiliency S | cvebase.io