CVE-2024-47119: IBM Storage Defender - Resiliency Service improper certificate validation
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9 does not properly validate a certificate which could allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client.
Other sources
IBM Storage Defender - Resiliency Service does not properly validate a certificate which could allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-47119?
CVE-2024-47119 is rated as a high severity vulnerability that can lead to potential certificate spoofing.
How do I fix CVE-2024-47119?
To mitigate CVE-2024-47119, upgrade IBM Storage Defender - Resiliency Service to version 2.0.10 or later.
What versions of IBM Storage Defender - Resiliency Service are affected by CVE-2024-47119?
CVE-2024-47119 affects IBM Storage Defender - Resiliency Service versions from 2.0.0 to 2.0.9 inclusive.
What type of vulnerability is CVE-2024-47119?
CVE-2024-47119 is a certificate validation vulnerability that allows spoofing of trusted entities.
What can an attacker do with CVE-2024-47119?
An attacker exploiting CVE-2024-47119 could intercept and manipulate communication between the client and host.