First published: Wed Dec 11 2024(Updated: )
IBM OpenPages may write sensitive information, under specific configurations, in clear text to the system tracing log files that could be obtained by a privileged user.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM OpenPages with Watson | <=9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-35117 is classified as a medium severity vulnerability due to the potential exposure of sensitive information.
To fix CVE-2024-35117, apply the recommended patch from IBM for OpenPages version 9.0.
CVE-2024-35117 affects IBM OpenPages with Watson version 9.0 when specific configurations are applied.
CVE-2024-35117 may expose sensitive information that is written in clear text in system tracing log files.
Yes, a privileged user may obtain sensitive information due to the insecure logging mechanism described in CVE-2024-35117.