First published: Fri Nov 22 2024(Updated: )
IBM Watson Query on Cloud Pak for Data 1.8, 2.0, 2.1, 2.2 and IBM Db2 Big SQL on Cloud Pak for Data 7.3, 7.4, 7.5, and 7.6 could allow an authenticated user to obtain sensitive information due to insufficient session expiration.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Watson Query on Cloud Pak for Data | <=2.2 | |
IBM Watson Query on Cloud Pak for Data | <=2.1 | |
IBM Watson Query on Cloud Pak for Data | <=2.0 | |
IBM Data Virtualization on Cloud Pak for Data | <=1.8 | |
IBM Big SQL | =7.3 | |
IBM Big SQL | =7.4 | |
IBM Big SQL | =7.5 | |
IBM Big SQL | =7.6 | |
Ibm Watson Query With Cloud Pak For Data | =1.8 | |
Ibm Watson Query With Cloud Pak For Data | =2.0 | |
Ibm Watson Query With Cloud Pak For Data | =2.1 | |
Ibm Watson Query With Cloud Pak For Data | =2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-35160 is considered to be medium due to the risk of unauthorized access to sensitive information.
To fix CVE-2024-35160, ensure that session expiration is properly configured and enforced in the affected IBM products.
CVE-2024-35160 affects IBM Watson Query on Cloud Pak for Data versions 1.8 to 2.2 and IBM Db2 Big SQL versions 7.3 to 7.6.
CVE-2024-35160 is a vulnerability related to insufficient session expiration for authenticated users.
Yes, authenticated users may exploit CVE-2024-35160 to obtain sensitive information due to session management issues.