PT-2024-4817 · Ibm · Ibm Infosphere Information Server

·

CVE-2024-31898

·

Published

2024-06-30

·

Updated

2024-07-31

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: IBM InfoSphere Information Server version 11.7
Description: The issue is related to an error in handling user-controlled authorization keys, which could allow a remote attacker to disclose protected information or modify arbitrary data. It is also described as allowing an authenticated user to read or modify sensitive information by bypassing authentication using insecure direct object references.
Recommendations: For IBM InfoSphere Information Server version 11.7, consider restricting access to sensitive information and implementing additional authentication measures to prevent bypassing authentication using insecure direct object references. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-05341
CVE-2024-31898

Affected Products

Ibm Infosphere Information Server