4.7
CVE-2024-54173
- EPSS 0.01%
- Published 28.02.2025 03:15:09
- Last modified 03.07.2025 20:44:08
- Source psirt@us.ibm.com
- Teams watchlist Login
- Open Login
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD reveals potentially sensitive information in trace files that could be read by a local user when webconsole trace is enabled.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users. Login
Data is provided by the National Vulnerability Database (NVD)
Ibm ≫ Mq Appliance SwEditioncontinuous_delivery Version < 9.4.2
Ibm ≫ Mq Appliance SwEditionlts Version >= 9.3.0.0 < 9.3.0.27
Ibm ≫ Mq Appliance SwEditionlts Version >= 9.4.0.0 < 9.4.0.10
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.01% | 0.013 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
psirt@us.ibm.com | 4.7 | 1 | 3.6 |
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-1323 Improper Management of Sensitive Trace Data
Trace data collected from several sources on the System-on-Chip (SoC) is stored in unprotected locations or transported to untrusted agents.