First published: Wed Dec 18 2024(Updated: )
IBM Security Guardium 11.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM InfoSphere Guardium z/OS | =11.5 | |
IBM InfoSphere Guardium z/OS | <=11.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-49336 is considered high due to the potential for server-side request forgery (SSRF) attacks.
To fix CVE-2024-49336, upgrade your IBM Security Guardium to a version that addresses the vulnerability.
IBM Security Guardium version 11.5 is the affected software for CVE-2024-49336.
The risks associated with CVE-2024-49336 include unauthorized requests being sent from the vulnerable system, potentially leading to network enumeration.
CVE-2024-49336 requires authenticated access, meaning an attacker must log in to exploit the vulnerability.