CVE-2024-49354

CWE-2133 documents3 sources
Severity
7.5HIGH
EPSS
0.1%
top 70.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 18

Description

IBM Concert 1.0.0, 1.0.1, and 1.0.2 is vulnerable to sensitive information disclosure through specially crafted API Calls.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

NVDibm/concert1.0.0, 1.0.1, 1.0.2+2
CVEListV5ibm/concert_software1.0.0, 1.0.1, 1.0.2

🔴Vulnerability Details

2
CVEList
IBM Concert information disclosure2025-01-18
GHSA
GHSA-jmh6-3m65-qgmg: IBM Concert 12025-01-18
CVE-2024-49354 (HIGH CVSS 7.5) | IBM Concert 1.0.0 | cvebase.io