CVE-2024-52363
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Jan 17, 2025
CWE ID 22
Summary
CVE-2024-52363 is a vulnerability affecting IBM InfoSphere Information Server version 11.7. This issue enables a remote attacker to traverse directories on the system by sending a specially crafted URL request containing "dot dot" sequences (/../). Successful exploitation could allow the attacker to view arbitrary files, potentially leading to sensitive information disclosure or further system compromise. IBM strongly encourages users to update to a patched version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.