CVE-2024-39727

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Dec 25, 2024
Updated: Jan 10, 2025
CWE ID 1022

Summary

CVE-2024-39727 is a vulnerability affecting IBM Engineering Lifecycle Optimization - Engineering Insights versions 7.0.2 and 7.0.3. The issue arises from the use of an untrusted external web link within the software. A remote attacker can capitalize on this flaw to expose sensitive information or gain unauthorized access to victims' web browsers. This vulnerability poses a significant risk and requires immediate attention from IBM and its users to apply the necessary patches or mitigations.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share