CVE-2024-35155: IBM MQ information disclosure
IBM MQ Console 9.3 LTS and 9.3 CD could disclose could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 292765.
Other sources
IBM MQ Console could disclose could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35155?
CVE-2024-35155 has been classified as a medium severity vulnerability.
How do I fix CVE-2024-35155?
To fix CVE-2024-35155, apply the latest patches and updates from IBM for affected MQ versions.
What are the affected versions of IBM MQ for CVE-2024-35155?
CVE-2024-35155 affects IBM MQ Console versions 9.3 LTS and 9.3 CD.
Can CVE-2024-35155 lead to further attacks?
Yes, CVE-2024-35155 can allow remote attackers to obtain sensitive information that may lead to further attacks.
Is sensitive information disclosed during CVE-2024-35155 exploitation?
Yes, during the exploitation of CVE-2024-35155, detailed technical error messages may disclose sensitive information.