CVE-2024-52897

IBM MQ 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.2 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
ibmCNA
6.2 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 4%
VendorProductVersion
ibmmq
9.2.0.0 ≤
𝑥
≤ 9.2.0.30
ibmmq
9.3.0 ≤
𝑥
≤ 9.4.1
ibmmq
9.3.0.0 ≤
𝑥
≤ 9.3.0.26
ibmmq
9.4.0.0 ≤
𝑥
≤ 9.4.0.7
𝑥
= Vulnerable software versions