CVE-2024-41766

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jan 4, 2025
CWE ID 1333

Summary

CVE-2024-41766 is a newly disclosed vulnerability in IBM Engineering Lifecycle Optimization - Publishing versions 7.0.2 and 7.0.3. An attacker can exploit this issue by employing a complex regular expression, leading to a denial of service condition. IBM recommends users address this vulnerability promptly to prevent potential disruptions. The exact nature of the regular expression and the specific denial of service mechanism have not been disclosed to maintain security. Organizations utilizing these affected versions are advised to upgrade to a patched version as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share