CVE-2024-35160: IBM Watson Query on Cloud Pak for Data and IBM Db2 Big SQL on Cloud Pak for Data information disclosure
IBM Watson Query on Cloud Pak for Data 1.8, 2.0, 2.1, 2.2 and IBM Db2 Big SQL on Cloud Pak for Data 7.3, 7.4, 7.5, and 7.6 could allow an authenticated user to obtain sensitive information due to insufficient session expiration.
Other sources
IBM Watson Query on Cloud Pak for Data could allow an authenticated user to obtain sensitive information due to insufficient session expiration.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35160?
The severity of CVE-2024-35160 is considered to be medium due to the risk of unauthorized access to sensitive information.
How do I fix CVE-2024-35160?
To fix CVE-2024-35160, ensure that session expiration is properly configured and enforced in the affected IBM products.
Which IBM products are affected by CVE-2024-35160?
CVE-2024-35160 affects IBM Watson Query on Cloud Pak for Data versions 1.8 to 2.2 and IBM Db2 Big SQL versions 7.3 to 7.6.
What type of vulnerability is CVE-2024-35160?
CVE-2024-35160 is a vulnerability related to insufficient session expiration for authenticated users.
Can authenticated users exploit CVE-2024-35160?
Yes, authenticated users may exploit CVE-2024-35160 to obtain sensitive information due to session management issues.