CVE-2024-52896: IBM MQ information disclosure
IBM MQ 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned.
Other sources
IBM MQ web console could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52896?
CVE-2024-52896 is considered a medium severity vulnerability due to the potential for sensitive information disclosure.
How do I fix CVE-2024-52896?
To mitigate CVE-2024-52896, upgrade IBM MQ to a version beyond 9.4 LTS or 9.4 CD to avoid detailed technical error message leaks.
Who is affected by CVE-2024-52896?
CVE-2024-52896 affects users of IBM MQ versions 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD.
What types of attacks can exploit CVE-2024-52896?
CVE-2024-52896 can be exploited by remote attackers to potentially gain access to sensitive information through detailed error messages.
Is there a workaround for CVE-2024-52896 until a patch is applied?
Currently, it is recommended to restrict access to the IBM MQ web console to prevent information leakage related to CVE-2024-52896.