First published: Mon Nov 25 2024(Updated: )
IBM Workload Scheduler 9.5, 10.1, and 10.2 stores user credentials in plain text which can be read by a local user.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Workload Scheduler | <=9.5 to 9.5.0.6 | |
IBM Workload Scheduler | <=10.1 to 10.1.0.4 | |
IBM Workload Scheduler | <=10.2 to 10.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-49351 is considered a high-severity vulnerability due to storing user credentials in plain text.
To fix CVE-2024-49351, update to a secured version of IBM Workload Scheduler that does not store credentials in plain text.
CVE-2024-49351 affects IBM Workload Scheduler versions 9.5, 10.1, and 10.2 up to their specified patch levels.
Local users of IBM Workload Scheduler are impacted by CVE-2024-49351 because they can read the stored plain text credentials.
The risks of CVE-2024-49351 include unauthorized access to sensitive data due to exposed user credentials.