CVE-2024-52898: IBM MQ information disclosure
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a local user to obtain sensitive information when a detailed technical error message is returned.
Other sources
IBM MQ web console could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52898?
CVE-2024-52898 has been classified as a medium-severity vulnerability affecting IBM MQ.
How do I fix CVE-2024-52898?
To fix CVE-2024-52898, users should apply the latest IBM MQ patches or updates provided by IBM.
Who is affected by CVE-2024-52898?
CVE-2024-52898 affects local and remote users of IBM MQ versions 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD.
What information can be exposed by CVE-2024-52898?
CVE-2024-52898 can potentially disclose sensitive information through detailed technical error messages.
Is CVE-2024-52898 being actively exploited?
As of the latest information, there are no confirmed reports of CVE-2024-52898 being actively exploited in the wild.