CVE-2024-49354: IBM Concert information disclosure
Published Oct 25, 2024
·Updated
IBM Concert 1.0.0, 1.0.1, and 1.0.2 is vulnerable to sensitive information disclosure through specially crafted API Calls.
Other sources
IBM Concert is vulnerable to sensitive information disclosure through specially crafted API Calls.
— IBM
Affected Software
4 affected components
IBM Concert Software<=1.0.0 - 1.0.1 - 1.0.2
IBM Concert=1.0.0
IBM Concert=1.0.1
IBM Concert=1.0.2
Event History
Oct 25, 2024
CVE Published
via IBM·12:00 AM
Jan 18, 2025
CVE Published
via MITRE·03:17 PM
Data Sourced
via MITRE·03:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-49354?
CVE-2024-49354 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2024-49354?
To fix CVE-2024-49354, upgrade to a version of IBM Concert Software that is higher than 1.0.2.
3
What types of information are disclosed by CVE-2024-49354?
CVE-2024-49354 can lead to the disclosure of sensitive user information through manipulated API calls.
4
Which versions of IBM Concert Software are affected by CVE-2024-49354?
Versions 1.0.0, 1.0.1, and 1.0.2 of IBM Concert Software are affected by CVE-2024-49354.
5
Is there a known exploit for CVE-2024-49354?
Currently, there are no publicly available exploits specifically targeting CVE-2024-49354.