Vulnerability identifier: #VU102028
Vulnerability risk: Medium
CVSSv4.0: 1.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2024-39727
CWE-ID:
CWE-1022
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
Engineering Lifecycle Optimization - Engineering Insights
Server applications /
Other server solutions
Vendor: IBM Corporation
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to application uses a web link with untrusted references to an external site. A remote attacker could exploit this vulnerability to expose sensitive information or perform unauthorized actions on the victims’ web browser.
Mitigation
Install updates from vendor's website.
Vulnerable software versions
Engineering Lifecycle Optimization - Engineering Insights: 7.0.2 - 7.0.3
External links
https://www.ibm.com/support/pages/node/7176783
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.