CVE-2024-52363

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Jan 17, 2025
CWE ID 22

Summary

CVE-2024-52363 is a vulnerability affecting IBM InfoSphere Information Server version 11.7. This issue enables a remote attacker to traverse directories on the system by sending a specially crafted URL request containing "dot dot" sequences (/../). Successful exploitation could allow the attacker to view arbitrary files, potentially leading to sensitive information disclosure or further system compromise. IBM strongly encourages users to update to a patched version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share