CVE-2024-54173
CVSS 3.1 Score 4.7 of 10 (medium)
Details
Published Feb 28, 2025
CWE ID 1323
Summary
CVE-2024-54173 is a vulnerability affecting IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD. When the webconsole trace feature is enabled, these versions reveal potentially sensitive information in trace files that can be read locally by users. This issue could lead to unintended disclosure of data, increasing the risk of information theft or unauthorized access. IBM strongly recommends disabling the webconsole trace feature as a mitigation measure until a patch is available.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- IBM MQ
Affected Vendors
- IBM Corporation