CVE-2024-28787: IBM Security Verify Access information disclosure
IBM Security Verify Access 10.0.0 through 10.0.7 and IBM Application Gateway 20.01 through 24.03 could allow a remote attacker to obtain highly sensitive private information or cause a denial of service using a specially crafted HTTP request. IBM X-Force ID: 286584.
Other sources
IBM Security Verify could allow a remote attacker to obtain highly sensitive private information or cause a denial of service using a specially crafted HTTP request.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28787?
CVE-2024-28787 has a high severity rating as it allows remote attackers to access sensitive information or cause a denial of service.
How do I fix CVE-2024-28787?
To fix CVE-2024-28787, upgrade IBM Security Verify Access and IBM Application Gateway to their latest patched versions.
Which versions of IBM Security Verify Access are affected by CVE-2024-28787?
IBM Security Verify Access versions 10.0.0 through 10.0.7 are affected by CVE-2024-28787.
Which versions of IBM Application Gateway are vulnerable to CVE-2024-28787?
IBM Application Gateway versions 20.01 through 24.03 are vulnerable to CVE-2024-28787.
Can CVE-2024-28787 be exploited remotely?
Yes, CVE-2024-28787 can be exploited remotely using specially crafted HTTP requests.