CVE-2024-54173CWE-1323

IBM MQ information disclosure

Medium · published February 28, 2025

CVSS v3.1
4.7
EPSS
0%
Percentile
2.5
In the wild
Unconfirmed
What it is

IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD reveals potentially sensitive information in trace files that could be read by a local user when webconsole trace is enabled.

The record
Technical detail
CVSS v3.1
4.7 · MEDIUM
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00125 · 2.5th percentile
Weakness
CWE-1323 · Improper Management of Sensitive Trace Data
Published
2025-02-28T02:22Z
EPSS history
Timeline
  • 28 FEB 02:22Z
    IBM MQ information disclosure
    cvelistv5