CVE-2024-52363: IBM InfoSphere Information Server directory traversal
IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
Other sources
IBM InfoSphere Information Server could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52363?
CVE-2024-52363 has a medium severity rating, indicating it presents a potential risk to affected systems.
How do I fix CVE-2024-52363?
To fix CVE-2024-52363, apply the security patches provided by IBM for InfoSphere Information Server 11.7.
What systems are affected by CVE-2024-52363?
CVE-2024-52363 affects IBM InfoSphere Information Server version 11.7.
What kind of attack does CVE-2024-52363 enable?
CVE-2024-52363 enables remote attackers to perform directory traversal attacks, potentially exposing sensitive files.
Is CVE-2024-52363 easily exploitable?
Yes, CVE-2024-52363 is considered easily exploitable due to its reliance on specially crafted URL requests.