PT-2024-5093 · Ibm · Ibm Datacap Navigator
Published
2024-07-12
·
Updated
2024-07-16
·
CVE-2024-39737
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
IBM Datacap Navigator versions 9.1.5 through 9.1.9
Description:
The issue is related to the error reporting mechanism in IBM Datacap Navigator, which could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
Recommendations:
For versions 9.1.5 through 9.1.9, consider restricting access to detailed technical error messages to minimize the risk of exploitation. As a temporary workaround, disabling the display of detailed error messages in the browser could help mitigate the issue until a patch is available.
Fix
Generation of Error Message Containing Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Datacap Navigator