CVE-2024-52361: IBM Storage Defender - Resiliency Service information disclosure
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9
stores user credentials in plain text which can be read by an authenticated user with access to the pod.
Other sources
IBM Storage Defender - Resiliency Service stores user credentials in plain text which can be read by an authenticated user with access to the pod.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52361?
CVE-2024-52361 has a high severity rating due to the exposure of user credentials in plain text.
How do I fix CVE-2024-52361?
To fix CVE-2024-52361, upgrade IBM Storage Defender - Resiliency Service to version 2.1.0 or higher where credentials are stored securely.
What versions of IBM Storage Defender - Resiliency Service are affected by CVE-2024-52361?
CVE-2024-52361 affects versions 2.0.0 through 2.0.9 of IBM Storage Defender - Resiliency Service.
Who is at risk from CVE-2024-52361?
Authenticated users with access to the affected pods are at risk from CVE-2024-52361 as they can read stored plain text credentials.
What impact does CVE-2024-52361 have on security?
CVE-2024-52361 compromises user credential confidentiality, which can lead to unauthorized access and potential data breaches.