4.7
CVE-2024-54173
- EPSS 0.02%
- Veröffentlicht 28.02.2025 03:15:09
- Zuletzt bearbeitet 03.07.2025 20:44:08
- Quelle psirt@us.ibm.com
- CVE-Watchlists
- Unerledigt
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD reveals potentially sensitive information in trace files that could be read by a local user when webconsole trace is enabled.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Mq Appliance SwEditioncontinuous_delivery Version < 9.4.2
Ibm ≫ Mq Appliance SwEditionlts Version >= 9.3.0.0 < 9.3.0.27
Ibm ≫ Mq Appliance SwEditionlts Version >= 9.4.0.0 < 9.4.0.10
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.02% | 0.025 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| psirt@us.ibm.com | 4.7 | 1 | 3.6 |
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-1323 Improper Management of Sensitive Trace Data
Trace data collected from several sources on the System-on-Chip (SoC) is stored in unprotected locations or transported to untrusted agents.