CVE-2023-24964: IBM InfoSphere Information Server information disclosure
Published Feb 8, 2023
·Updated
IBM InfoSphere Information Server 11.7 could allow a local user to obtain sensitive information from a log files. IBM X-Force ID: 246463.
Other sources
IBM InfoSphere Information Server could allow a local user to obtain sensitive information from a log files.
Affected Software
5 affected componentsFixes available
IBM InfoSphere Information Server<=11.7
IBM InfoSphere Information Server=11.7
IBM AIX
Linux Linux kernel
Microsoft Windows
Remediation
Patch Available
Event History
Feb 8, 2023
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionSeverityAffected Software
Feb 17, 2023
CVE Published
via MITRE·04:35 PM
Data Sourced
via MITRE·04:35 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-24964?
The severity of CVE-2023-24964 is medium with a severity value of 6.2.
2
How does CVE-2023-24964 affect IBM InfoSphere Information Server?
CVE-2023-24964 affects IBM InfoSphere Information Server version 11.7.
3
How can a local user exploit CVE-2023-24964?
A local user can exploit CVE-2023-24964 to obtain sensitive information from log files.
4
Is IBM InfoSphere Information Server version 11.7 vulnerable to CVE-2023-24964?
Yes, IBM InfoSphere Information Server version 11.7 is vulnerable to CVE-2023-24964.
5
How can I fix CVE-2023-24964?
To fix CVE-2023-24964, apply the patch provided by IBM at [https://www.ibm.com/support/pages/node/878310](https://www.ibm.com/support/pages/node/878310).