CVE-2024-39727
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Dec 25, 2024
Updated: Jan 10, 2025
CWE ID 1022
Summary
CVE-2024-39727 is a vulnerability affecting IBM Engineering Lifecycle Optimization - Engineering Insights versions 7.0.2 and 7.0.3. The issue arises from the use of an untrusted external web link within the software. A remote attacker can capitalize on this flaw to expose sensitive information or gain unauthorized access to victims' web browsers. This vulnerability poses a significant risk and requires immediate attention from IBM and its users to apply the necessary patches or mitigations.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- IBM Corporation