216.73.216.36

CVE-2024-52891

· Published 07/01/2025 12:15 · Modified 04/03/2025 20:04

Labels: CVE-2024-52891 2025-01-07CVE-2024-52891CWE-116CWE-117[email protected]

Essential information

Published
07/01/2025 12:15
Modified
04/03/2025 20:04
Author
Creator
CVSS
5.4 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

CVSS metrics

Description

IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3 could allow an authenticated user to inject malicious information or obtain information from log files due to improper log neutralization.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
ibm / concert software cpe:2.3:a:ibm:concert_software:1.0.0:*:*:*:*:*:*:*
ibm / concert software cpe:2.3:a:ibm:concert_software:1.0.1:*:*:*:*:*:*:*
ibm / concert software cpe:2.3:a:ibm:concert_software:1.0.2:*:*:*:*:*:*:*
ibm / concert software cpe:2.3:a:ibm:concert_software:1.0.2.1:*:*:*:*:*:*:*
ibm / concert software cpe:2.3:a:ibm:concert_software:1.0.3:*:*:*:*:*:*:*

References