First published: Tue Jan 14 2025(Updated: )
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a local user to obtain sensitive information when a detailed technical error message is returned.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM MQ | <=9.4 LTS | |
IBM MQ | <=9.4 CD | |
IBM MQ | <=9.3 LTS | |
IBM MQ | <=9.3 CD |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-52898 has been classified as a medium-severity vulnerability affecting IBM MQ.
To fix CVE-2024-52898, users should apply the latest IBM MQ patches or updates provided by IBM.
CVE-2024-52898 affects local and remote users of IBM MQ versions 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD.
CVE-2024-52898 can potentially disclose sensitive information through detailed technical error messages.
As of the latest information, there are no confirmed reports of CVE-2024-52898 being actively exploited in the wild.