CVE-2024-52896

IBM MQ 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned.
References
Link Resource
https://www.ibm.com/support/pages/node/7179152 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:ibm:mq:*:*:*:*:lts:*:*:*
cpe:2.3:a:ibm:mq:*:*:*:*:continuous_delivery:*:*:*
cpe:2.3:a:ibm:mq:*:*:*:*:lts:*:*:*
cpe:2.3:a:ibm:mq:*:*:*:*:lts:*:*:*
OR cpe:2.3:o:ibm:linux_on_ibm_z:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

03 Jul 2025, 19:52

Type Values Removed Values Added
CPE cpe:2.3:o:ibm:linux_on_ibm_z:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:*:*:*:*:lts:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:*:*:*:*:continuous_delivery:*:*:*
First Time Linux linux Kernel
Linux
Microsoft windows
Microsoft
Ibm
Ibm linux On Ibm Z
Ibm mq
References () https://www.ibm.com/support/pages/node/7179152 - () https://www.ibm.com/support/pages/node/7179152 - Vendor Advisory

10 Jan 2025, 15:15

Type Values Removed Values Added
References
  • {'url': 'https://www.ibm.com/support/pages/node/7178244', 'source': 'psirt@us.ibm.com'}
  • () https://www.ibm.com/support/pages/node/7179152 -
Summary
  • (es) La consola web de IBM MQ Appliance 9.3 LTS, 9.3 CD, 9.4 LTS y 9.4 CD podría permitir que un atacante remoto obtenga información confidencial cuando se devuelve un mensaje de error técnico detallado.
Summary (en) IBM MQ Appliance 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned. (en) IBM MQ 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned.

19 Dec 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-19 17:15

Updated : 2025-08-19 21:31


NVD link : CVE-2024-52896

Mitre link : CVE-2024-52896

CVE.ORG link : CVE-2024-52896


JSON object : View

Products Affected

linux

  • linux_kernel

microsoft

  • windows

ibm

  • linux_on_ibm_z
  • mq
CWE
CWE-209

Generation of Error Message Containing Sensitive Information