CVE-2024-52896

CWE-2093 documents3 sources
Severity
6.2MEDIUM
EPSS
0.0%
top 91.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 19

Description

IBM MQ 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.5 | Impact: 3.6

Affected Packages2 packages

NVDibm/mq9.2.0.09.2.0.30+3
CVEListV5ibm/mq9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, 9.4 CD

🔴Vulnerability Details

2
GHSA
GHSA-28pp-6j97-mmc8: IBM MQ Appliance 92024-12-19
CVEList
IBM MQ information disclosure2024-12-19
CVE-2024-52896 (MEDIUM CVSS 6.2) | IBM MQ 9.2 LTS | cvebase.io