cbcvebase.
CVE-2024-52897
published 2024-12-19

CVE-2024-52897: IBM MQ 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a remote attacker to obtain sensitive information when a detailed technical error…

PriorityP423medium6.2CVSS 3.1
AVLACLPRNUINSUCHINAN
EPSS
0.21%
10.6th percentile
IBM MQ 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned.

Affected

5 ranges
VendorProductVersion rangeFixed in
ibmmq
ibmmq>= 9.2.0.0 < 9.2.0.309.2.0.30
ibmmq>= 9.3.0 < 9.4.19.4.1
ibmmq>= 9.3.0.0 < 9.3.0.269.3.0.26
ibmmq>= 9.4.0.0 < 9.4.0.79.4.0.7
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.