CVE-2024-39725

IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
References
Link Resource
https://www.ibm.com/support/pages/node/7176782 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:engineering_lifecycle_optimization_-_engineering_insights:7.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:engineering_lifecycle_optimization_-_engineering_insights:7.0.3:*:*:*:*:*:*:*

History

10 Jan 2025, 20:14

Type Values Removed Values Added
Summary
  • (es) IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 y 7.0.3 podría permitir a un atacante remoto obtener información confidencial cuando se devuelve un mensaje de error técnico detallado en el navegador. Esta información podría usarse en futuros ataques contra el sistema.
First Time Ibm
Ibm engineering Lifecycle Optimization - Engineering Insights
CPE cpe:2.3:a:ibm:engineering_lifecycle_optimization_-_engineering_insights:7.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:engineering_lifecycle_optimization_-_engineering_insights:7.0.3:*:*:*:*:*:*:*
References () https://www.ibm.com/support/pages/node/7176782 - () https://www.ibm.com/support/pages/node/7176782 - Vendor Advisory

25 Dec 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-25 14:15

Updated : 2025-01-10 20:14


NVD link : CVE-2024-39725

Mitre link : CVE-2024-39725

CVE.ORG link : CVE-2024-39725


JSON object : View

Products Affected

ibm

  • engineering_lifecycle_optimization_-_engineering_insights
CWE
CWE-209

Generation of Error Message Containing Sensitive Information