CVE-2024-40689: IBM InfoSphere Information Server SQL injection
IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. IBM X-Force ID: 297719.
Other sources
IBM InfoSphere Server is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-40689?
CVE-2024-40689 has a high severity level due to its potential for SQL injection vulnerabilities.
How do I fix CVE-2024-40689?
To fix CVE-2024-40689, apply the security patch provided by IBM for InfoSphere Information Server version 11.7.
What types of attacks can be executed using CVE-2024-40689?
Exploiting CVE-2024-40689 enables attackers to perform SQL injection, which can lead to unauthorized viewing, adding, modifying, or deleting of database information.
Which versions of IBM InfoSphere are affected by CVE-2024-40689?
CVE-2024-40689 affects IBM InfoSphere Information Server version 11.7.
Is CVE-2024-40689 being actively exploited in the wild?
Currently, there is no public information confirming that CVE-2024-40689 is being actively exploited, but it is recommended to apply updates promptly.