CVE-2024-52891: IBM Concert Software log manipulation
IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3
could allow an authenticated user to inject malicious information or obtain information from log files due to improper log neutralization.
Other sources
IBM Concert Software could allow an authenticated user to inject malicious information or obtain information from log files due to improper log neutralization.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52891?
CVE-2024-52891 has a high severity rating due to potential information disclosure and injection vulnerabilities.
How do I fix CVE-2024-52891?
To fix CVE-2024-52891, upgrade IBM Concert Software to a version later than 1.0.3.
Who is affected by CVE-2024-52891?
CVE-2024-52891 affects users of IBM Concert Software versions 1.0.0 through 1.0.3.
What type of vulnerability is CVE-2024-52891?
CVE-2024-52891 is classified as an improper log neutralization vulnerability.
Can an unauthenticated user exploit CVE-2024-52891?
No, CVE-2024-52891 can only be exploited by an authenticated user.