CVE-2024-49351: IBM Workload Scheduler information disclosure
IBM Workload Scheduler 9.5, 10.1, and 10.2 stores user credentials in plain text which can be read by a local user.
Other sources
IBM Workload Scheduler stores user credentials in plain text which can be read by a local user.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-49351?
CVE-2024-49351 is considered a high-severity vulnerability due to storing user credentials in plain text.
How do I fix CVE-2024-49351?
To fix CVE-2024-49351, update to a secured version of IBM Workload Scheduler that does not store credentials in plain text.
What versions of IBM Workload Scheduler are affected by CVE-2024-49351?
CVE-2024-49351 affects IBM Workload Scheduler versions 9.5, 10.1, and 10.2 up to their specified patch levels.
Who is impacted by CVE-2024-49351?
Local users of IBM Workload Scheduler are impacted by CVE-2024-49351 because they can read the stored plain text credentials.
What are the risks associated with CVE-2024-49351?
The risks of CVE-2024-49351 include unauthorized access to sensitive data due to exposed user credentials.