CVE-2024-52361

MEDIUM

IBM Storage Defender - Resiliency Service <2.0.10 - Info Disclosure

Title source: llm
STIX 2.1

Description

IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9  stores user credentials in plain text which can be read by an authenticated user with access to the pod.

Scores

CVSS v3 5.7
EPSS 0.0005
EPSS Percentile 16.1%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-256
Status published
Products (1)
ibm/storage_defender_resiliency_service 2.0 - 2.0.9
Published Dec 18, 2024
Tracked Since Feb 18, 2026