CVE-2024-41767: IBM Engineering Lifecycle Optimization - Publishing SQL injection
IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
Other sources
IBM Engineering Lifecycle Optimization - Publishing is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41767?
CVE-2024-41767 is rated as a critical vulnerability due to its potential for remote SQL injection attacks.
How do I fix CVE-2024-41767?
To fix CVE-2024-41767, upgrade IBM Engineering Lifecycle Optimization - Publishing to versions 7.0.4 or later.
Who is affected by CVE-2024-41767?
CVE-2024-41767 affects users of IBM Engineering Lifecycle Optimization - Publishing versions 7.0.2 and 7.0.3.
What impact does CVE-2024-41767 have on organizations?
CVE-2024-41767 allows remote attackers to manipulate the back-end database, potentially leading to data loss or unauthorized access.
What type of vulnerability is CVE-2024-41767?
CVE-2024-41767 is categorized as an SQL injection vulnerability.