CVE-2024-52897: IBM MQ information disclosure
IBM MQ 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned.
Other sources
IBM MQ web console could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52897?
CVE-2024-52897 has a medium severity rating due to the potential for remote attackers to access sensitive information.
How do I fix CVE-2024-52897?
To fix CVE-2024-52897, upgrade to a patched version of IBM MQ that resolves the information disclosure vulnerability.
What versions of IBM MQ are affected by CVE-2024-52897?
CVE-2024-52897 affects IBM MQ versions 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD.
Can CVE-2024-52897 lead to data breaches?
Yes, CVE-2024-52897 can potentially lead to data breaches by exposing sensitive information to remote attackers.
What type of vulnerability is CVE-2024-52897?
CVE-2024-52897 is an information disclosure vulnerability that arises when detailed error messages are returned to users.