CVE-2024-54169

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Feb 27, 2025
CWE ID 22

Summary

CVE-2024-54169 is a vulnerability affecting IBM EntireX 11.1. This issue grants authenticated attackers the ability to traverse directories on the system. By sending specially crafted URL requests containing "dot dot" sequences (/../), an attacker can view arbitrary files, potentially leading to unauthorized access or information disclosure. IBM EntireX users are advised to apply the necessary patches or updates to mitigate this risk. Unprotected systems are susceptible to confidential data exposure.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share