CVE-2024-52898

CVSS 3.1 Score 6.2 of 10 (medium)

Details

Published Jan 14, 2025
CWE ID 209

Summary

CVE-2024-52898 is a vulnerability affecting IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console. A local user can exploit this issue by causing the console to return a detailed technical error message. This message may contain sensitive information that should not be publicly accessible. The vulnerability poses a risk to the confidentiality of data managed by the affected IBM MQ servers. IBM recommends applying the available patches to mitigate this issue. In summary, IBM MQ web console versions 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD have a vulnerability (CVE-2024-52898) which can allow a local user to access sensitive information by triggering a detailed technical error message. The exposure of this data could adversely impact data confidentiality. IBM suggests applying the relevant patches to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share