PT-2024-4961 · Ibm · Ibm Datacap Navigator

Published

2024-07-12

·

Updated

2024-07-16

·

CVE-2024-39740

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: IBM Datacap Navigator versions 9.1.5 through 9.1.9
Description: The issue is related to the disclosure of system data to unauthorized individuals. It can be exploited by a remote attacker who sends specially crafted HTTP requests to reveal protected information. The vulnerability allows an attacker to gather information for future attacks against the system by displaying version information in HTTP requests.
Recommendations: For versions 9.1.5 through 9.1.9, consider restricting access to the system to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using the version information in HTTP requests. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2024-05485
CVE-2024-39740

Affected Products

Ibm Datacap Navigator