First published: Wed Apr 03 2024(Updated: )
IBM Security Verify Access 10.0.0 through 10.0.7 and IBM Application Gateway 20.01 through 24.03 could allow a remote attacker to obtain highly sensitive private information or cause a denial of service using a specially crafted HTTP request. IBM X-Force ID: 286584.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Verify Access | <=10.0.0 - 10.0.7 | |
IBM Security Verify Access | <=10.0.0 - 10.0.7 | |
IBM Application Gateway | <=20.01 - 24.03 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-28787 has a high severity rating as it allows remote attackers to access sensitive information or cause a denial of service.
To fix CVE-2024-28787, upgrade IBM Security Verify Access and IBM Application Gateway to their latest patched versions.
IBM Security Verify Access versions 10.0.0 through 10.0.7 are affected by CVE-2024-28787.
IBM Application Gateway versions 20.01 through 24.03 are vulnerable to CVE-2024-28787.
Yes, CVE-2024-28787 can be exploited remotely using specially crafted HTTP requests.