CVE-2024-37526: IBM Watson Query on Cloud Pak for Data information disclosure
IBM Watson Query on Cloud Pak for Data (IBM Data Virtualization 1.8, 2.0, 2.1, 2.2, and 3.0.0) could allow an authenticated user to obtain sensitive information from objects published using Watson Query due to an improper data protection mechanism.
Other sources
IBM Watson Query on Cloud Pak for Data could allow an authenticated user to obtain sensitive information from objects published using Watson Query due to an improper data protection mechanism.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37526?
CVE-2024-37526 is classified as a medium severity vulnerability.
How do I fix CVE-2024-37526?
To fix CVE-2024-37526, upgrade to the latest version of IBM Watson Query or IBM Data Virtualization that addresses the vulnerability.
Who is affected by CVE-2024-37526?
CVE-2024-37526 affects users of IBM Watson Query and IBM Data Virtualization on Cloud Pak for Data versions up to 3.0.0.
What type of vulnerability is CVE-2024-37526?
CVE-2024-37526 is a data exposure vulnerability that allows authenticated users to access sensitive information.
What versions of IBM products are impacted by CVE-2024-37526?
CVE-2024-37526 impacts IBM Watson Query on Cloud Pak for Data versions 1.8 through 2.2 and all versions of Data Virtualization up to 3.0.0.