CVE-2024-22349

CVSS 3.1 Score 4.0 of 10 (medium)

Attack Complexity low
Confidentiality low
Integrity none
Availability none
Scope unchanged
Privileges Required none

Details

Published Jan 20, 2025
CWE ID 525

Summary

CVE-2024-22349 is a vulnerability affecting IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity versions 4.0.0 through 4.0.25. This issue allows web pages to be stored locally on the system. If a user has access to another user's account, they could potentially read the locally stored pages, leading to a privacy breach. This vulnerability poses a risk to organizations that use these IBM tools and could result in unintended information disclosure. Users are advised to update to the latest version of these tools as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share