MEDIUM
IBM Jazz Foundation information disclosure
Published Jan 3, 2025
4.3
MEDIUMCVSS 3.1
EPSS 0.35%
Description
IBM Jazz Foundation 7.0.2, 7.0.3, and 7.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
Affected products
-
Affected
- 7.0.2, 7.0.3, 7.1.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| IBM | Jazz Foundation | unaffected | Affected
|
AND
OR
- 7.0.2
- 7.0.3
- 7.1.0
Running on/with
OR
- n/a
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-47153 Advisory
- https://www.ibm.com/support/pages/node/7180120 Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-47153 | Advisory | |
| https://www.ibm.com/support/pages/node/7180120 | Vendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ibm
Published Jan 3, 2025
Updated Jan 3, 2025
Reserved Jun 2, 2024
Link CVE-2024-5591
CISA Vulnrichment
Updated Jan 3, 2025
Red Hat
No data
GitHub
No data