CVE-2024-40704Insufficiently Protected Credentials in IBM Infosphere Information Server

Severity
4.9MEDIUMNVD
EPSS
0.1%
top 81.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 15

Description

IBM InfoSphere Information Server 11.7 could allow a privileged user to obtain sensitive information from authentication request headers. IBM X-Force ID: 298277.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:NExploitability: 1.2 | Impact: 3.6

Affected Packages2 packages

NVDibm/infosphere_information_server11.7, 11.7.0.1, 11.7.0.2+2

🔴Vulnerability Details

2
CVEList
IBM InfoSphere Information Server information disclosure2024-08-15
GHSA
GHSA-6267-jhgq-8f4c: IBM InfoSphere Information Server 112024-08-15
CVE-2024-40704 — Insufficiently Protected Credentials | cvebase