CVE-2024-54169
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Feb 27, 2025
CWE ID 22
Summary
CVE-2024-54169 is a vulnerability affecting IBM EntireX 11.1. This issue grants authenticated attackers the ability to traverse directories on the system. By sending specially crafted URL requests containing "dot dot" sequences (/../), an attacker can view arbitrary files, potentially leading to unauthorized access or information disclosure. IBM EntireX users are advised to apply the necessary patches or updates to mitigate this risk. Unprotected systems are susceptible to confidential data exposure.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.