First published: Tue Jul 23 2024(Updated: )
IBM DataStage Flow Designer could allow a privileged user to obtain sensitive information from authentication request headers.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM InfoSphere Information Server | <=11.7 | |
IBM InfoSphere Information Server | =11.7 | |
IBM InfoSphere Information Server | =11.7.0.1 | |
IBM InfoSphere Information Server | =11.7.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-40704 has a moderate severity level due to potential exposure of sensitive information.
To fix CVE-2024-40704, apply the available security patch from IBM for InfoSphere Information Server 11.7.
CVE-2024-40704 affects IBM InfoSphere Information Server versions 11.7, 11.7.0.1, and 11.7.0.2.
CVE-2024-40704 allows privileged users to access sensitive information from authentication request headers.
Yes, additional information about CVE-2024-40704 can be found in IBM's security advisories and documentation.