CVE-2024-40704: IBM InfoSphere Information Server information disclosure
IBM DataStage Flow Designer could allow a privileged user to obtain sensitive information from authentication request headers.
Other sources
IBM InfoSphere Information Server 11.7 could allow a privileged user to obtain sensitive information from authentication request headers. IBM X-Force ID: 298277.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-40704?
CVE-2024-40704 has a moderate severity level due to potential exposure of sensitive information.
How do I fix CVE-2024-40704?
To fix CVE-2024-40704, apply the available security patch from IBM for InfoSphere Information Server 11.7.
Who is affected by CVE-2024-40704?
CVE-2024-40704 affects IBM InfoSphere Information Server versions 11.7, 11.7.0.1, and 11.7.0.2.
What types of data are exposed in CVE-2024-40704?
CVE-2024-40704 allows privileged users to access sensitive information from authentication request headers.
Can I find more information about CVE-2024-40704 from IBM?
Yes, additional information about CVE-2024-40704 can be found in IBM's security advisories and documentation.