CVE-2024-31916: IBM OpenBMC information disclosure
IBM OpenBMC FW1050.00 through FW1050.10 BMCWeb HTTPS server component could disclose sensitive URI content to an unauthorized actor that bypasses authentication channels. IBM X-ForceID: 290026.
Other sources
IBM OpenBMC's BMCWeb HTTPS server component could disclose sensitive URI content to an unauthorized actor that bypasses authentication channels.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-31916?
CVE-2024-31916 has a critical severity due to the potential exposure of sensitive URI content without proper authentication.
How can I mitigate CVE-2024-31916?
Mitigation for CVE-2024-31916 includes upgrading the IBM OpenBMC firmware to a version later than FW1050.10.
What is the potential impact of CVE-2024-31916?
The potential impact of CVE-2024-31916 includes unauthorized access to sensitive information via the BMCWeb HTTPS server.
Which versions of OpenBMC are affected by CVE-2024-31916?
CVE-2024-31916 affects IBM OpenBMC versions FW1050.00 through FW1050.10.
Who can be affected by CVE-2024-31916?
Users of IBM OpenBMC with the specified firmware versions could be affected by CVE-2024-31916 due to unauthorized URI content disclosure.