First published: Fri Jan 03 2025(Updated: )
IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to cause an unhandled SSL exception which could leave the connection in an unexpected or insecure state.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Pub | <=7.0.3 | |
IBM Pub | <=7.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-41768 is classified as a high-severity vulnerability due to the potential for remote exploitation leading to insecure connection states.
To remediate CVE-2024-41768, upgrade to version 7.0.4 or later of the IBM Engineering Lifecycle Optimization - Publishing product.
CVE-2024-41768 could allow remote attackers to exploit an unhandled SSL exception, potentially leading to a denial of service or unauthorized access.
CVE-2024-41768 affects IBM Engineering Lifecycle Optimization - Publishing versions 7.0.2 and 7.0.3.
There are no official workarounds for CVE-2024-41768, and it is recommended to apply the available patch as soon as possible.