CVE-2024-22352

CVSS 3.1 Score 5.5 of 10 (medium)

Attack Complexity low
Confidentiality high
Privileges Required low
Integrity none
Availability none
Scope unchanged

Details

Published Mar 21, 2024
Updated: Apr 1, 2024
CWE ID 532

Summary

CVE-2024-22352 is a vulnerability affecting IBM InfoSphere Information Server 11.7. This issue arises due to the software storing potentially sensitive information in log files, which can be accessed by a local user. IBM's X-Force team has assigned the ID 280361 to this vulnerability. The impact of this issue is heightened since local users have unauthorized access to sensitive data, potentially leading to data breaches or unauthorized system access. IBM is strongly encouraged to patch this vulnerability as soon as possible. Users should also consider implementing access controls to limit the exposure of log files containing sensitive data.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • IBM Infosphere Information Server

Affected Vendors

  • IBM Corporation