PT-2025-1195 · Ibm · Ibm Concert
Published
2025-01-06
·
Updated
2025-01-07
·
CVE-2024-52891
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Concert Software versions 1.0.0 through 1.0.3
Description
The issue is related to improper log neutralization, which could allow an authenticated user to inject malicious information or obtain information from log files. This is due to the incorrect handling of log registration outputs. Exploitation of the issue may enable a remote attacker to execute arbitrary commands.
Recommendations
For versions 1.0.0 through 1.0.3, consider disabling log registration functionality until a patch is available to prevent malicious information injection or unauthorized access to log files. Restrict access to log files to minimize the risk of exploitation. As a temporary workaround, limit the ability of authenticated users to interact with log files. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Concert