CVE-2024-41757

CVSS 3.1 Score 5.9 of 10 (medium)

Details

Published Jan 24, 2025
CWE ID 311

Summary

CVE-2024-41757 is a vulnerability affecting IBM Concert Software versions 1.0.0 and 1.0.1. This issue enables a remote attacker to obtain sensitive information by exploiting the failure to properly implement HTTP Strict Transport Security. The vulnerability can be exploited using man-in-the-middle techniques, allowing the attacker to intercept and read unencrypted data, potentially leading to serious data breaches. IBM has released patches to address this issue, and users are strongly encouraged to apply them as soon as possible to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share