CVE-2024-39739: IBM Datacap Navigator server-side request forgery
IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 296008.
Other sources
IBM Datacap Navigator is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39739?
CVE-2024-39739 is classified as a medium severity vulnerability due to the potential for unauthorized requests that can lead to further attacks.
How do I fix CVE-2024-39739?
To mitigate CVE-2024-39739, apply the latest security updates provided by IBM for Datacap Navigator and Datacap.
Who is affected by CVE-2024-39739?
CVE-2024-39739 affects multiple versions of IBM Datacap Navigator and Datacap, specifically from versions 9.1.5 to 9.1.9.
What type of vulnerability is CVE-2024-39739?
CVE-2024-39739 is a server-side request forgery (SSRF) vulnerability.
Can CVE-2024-39739 lead to other attacks?
Yes, CVE-2024-39739 can enable an attacker to perform network enumeration and facilitate additional attacks.