CVE-2024-52898

CWE-2093 documents3 sources
Severity
6.2MEDIUM
EPSS
0.0%
top 87.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 14

Description

IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a local user to obtain sensitive information when a detailed technical error message is returned.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.5 | Impact: 3.6

Affected Packages2 packages

NVDibm/mq9.3.09.4.1.1+2
CVEListV5ibm/mq9.3 LTS, 9.3 CD, 9.4 LTS, 9.4 CD

🔴Vulnerability Details

2
GHSA
GHSA-4gww-xwpq-hjpp: IBM MQ 92025-01-14
CVEList
IBM MQ information disclosure2025-01-14
CVE-2024-52898 (MEDIUM CVSS 6.2) | IBM MQ 9.3 LTS | cvebase.io