6.2
CVE-2024-40682
- EPSS 0.02%
- Veröffentlicht 23.07.2025 11:14:18
- Zuletzt bearbeitet 06.08.2025 19:45:24
- Quelle psirt@us.ibm.com
- CVE-Watchlists
- Unerledigt
IBM SmartCloud Analytics - Log Analysis denial of service
IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local user to cause a denial of service due to improper validation of specified type of input.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Smartcloud Analytics Log Analysis Version1.3.7.0
Ibm ≫ Smartcloud Analytics Log Analysis Version1.3.7.1
Ibm ≫ Smartcloud Analytics Log Analysis Version1.3.7.2
Ibm ≫ Smartcloud Analytics Log Analysis Version1.3.8.0
Ibm ≫ Smartcloud Analytics Log Analysis Version1.3.8.1
Ibm ≫ Smartcloud Analytics Log Analysis Version1.3.8.2
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.02% | 0.052 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
|
| psirt@us.ibm.com | 6.2 | 2.5 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-1287 Improper Validation of Specified Type of Input
The product receives input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.