PT-2025-1092 · Ibm · Ibm Engineering Lifecycle Optimization - Publishing

Published

2025-01-03

·

Updated

2025-01-04

·

CVE-2024-41768

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions IBM Engineering Lifecycle Optimization - Publishing versions 7.0.2 through 7.0.3
Description The issue is related to the implementation of TLS and SSL protocols in the software, which is associated with inadequate access control. Exploitation of this issue could allow a remote attacker to cause an unhandled SSL exception, potentially leaving the connection in an unexpected or insecure state.
Recommendations For versions 7.0.2 and 7.0.3, consider disabling the SSL functionality until a patch is available to prevent potential exploitation. Restrict access to the software to minimize the risk of exploitation by a remote attacker. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2025-00347
CVE-2024-41768

Affected Products

Ibm Engineering Lifecycle Optimization - Publishing